CVE-2022-28872: Address Bar Spoofing Vulnerability in F-Secure SAFE Browser for Android
Published May 12, 2022
·Updated
A vulnerability affecting F-Secure SAFE browser was discovered. A maliciously crafted website could make a phishing attack with address bar spoofing as the address bar was not correct if navigation fails in a loop.
Affected Software
1 affected component
F-Secure Safe Android<=19.0
Remediation
Information
FIX : A fix has been released in the automatic update channel since 3rd May 2022. No user action is required.
Event History
May 12, 2022
CVE Published
via MITRE·11:16 AM
Data Sourced
via MITRE·11:16 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-28872?
CVE-2022-28872 is a vulnerability affecting F-Secure SAFE browser that could allow a phishing attack with address bar spoofing.
2
How does CVE-2022-28872 work?
CVE-2022-28872 works by a maliciously crafted website exploiting a navigation loop failure in F-Secure SAFE browser to display a misleading address bar.
3
What is the severity of CVE-2022-28872?
The severity of CVE-2022-28872 is rated as high with a CVSS score of 8.8.
4
Which software is affected by CVE-2022-28872?
F-Secure SAFE browser version up to 19.0 on Android is affected by CVE-2022-28872.
5
How can I fix CVE-2022-28872?
To fix CVE-2022-28872, update F-Secure SAFE browser to the latest version available.