First published: Thu May 12 2022(Updated: )
A vulnerability affecting F-Secure SAFE browser was discovered. A maliciously crafted website could make a phishing attack with address bar spoofing as the address bar was not correct if navigation fails in a loop.
Credit: cve-notifications-us@f-secure.com
Affected Software | Affected Version | How to fix |
---|---|---|
F-secure Safe | <=19.0 |
FIX : A fix has been released in the automatic update channel since 3rd May 2022. No user action is required.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-28872 is a vulnerability affecting F-Secure SAFE browser that could allow a phishing attack with address bar spoofing.
CVE-2022-28872 works by a maliciously crafted website exploiting a navigation loop failure in F-Secure SAFE browser to display a misleading address bar.
The severity of CVE-2022-28872 is rated as high with a CVSS score of 8.8.
F-Secure SAFE browser version up to 19.0 on Android is affected by CVE-2022-28872.
To fix CVE-2022-28872, update F-Secure SAFE browser to the latest version available.