{"api_version":"1","generated_at":"2026-07-23T21:09:44+00:00","cve":"CVE-2018-18334","urls":{"html":"https://cve.report/CVE-2018-18334","api":"https://cve.report/api/cve/CVE-2018-18334.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-18334","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-18334"},"summary":{"title":"CVE-2018-18334","description":"A vulnerability in the Private Browser of Trend Micro Dr. Safety for Android (Consumer) versions below 3.0.1478 could allow an remote attacker to bypass the Same Origin Policy (SOP) and obtain sensitive information via crafted JavaScript code on vulnerable installations.","state":"PUBLIC","assigner":"security@trendmicro.com","published_at":"2019-02-05 22:29:00","updated_at":"2019-02-13 19:08:00"},"problem_types":["CWE-200"],"metrics":[],"references":[{"url":"https://esupport.trendmicro.com/en-us/home/pages/technical-support/1121933.aspx","name":"https://esupport.trendmicro.com/en-us/home/pages/technical-support/1121933.aspx","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Security Bulletin: Trend Micro Dr. Safety for Android (Consumer) SOP Bypass Vulnerability · Trend Micro for Home","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-18334","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-18334","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"18334","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"trendmicro","cpe5":"dr._safety","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"android","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"18334","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"trendmicro","cpe5":"dr._safety","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"android","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security@trendmicro.com","ID":"CVE-2018-18334","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Trend Micro Dr. Safety for Android (Consumer)","version":{"version_data":[{"version_value":"Before 3.0.1478"}]}}]},"vendor_name":"Trend Micro"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A vulnerability in the Private Browser of Trend Micro Dr. Safety for Android (Consumer) versions below 3.0.1478 could allow an remote attacker to bypass the Same Origin Policy (SOP) and obtain sensitive information via crafted JavaScript code on vulnerable installations."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"SOP Bypass"}]}]},"references":{"reference_data":[{"name":"https://esupport.trendmicro.com/en-us/home/pages/technical-support/1121933.aspx","refsource":"CONFIRM","url":"https://esupport.trendmicro.com/en-us/home/pages/technical-support/1121933.aspx"}]}},"nvd":{"publishedDate":"2019-02-05 22:29:00","lastModifiedDate":"2019-02-13 19:08:00","problem_types":["CWE-200"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:trendmicro:dr._safety:*:*:*:*:*:android:*:*","versionEndExcluding":"3.0.1478","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"18334","Ordinal":"135251","Title":"CVE-2018-18334","CVE":"CVE-2018-18334","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"18334","Ordinal":"1","NoteData":"A vulnerability in the Private Browser of Trend Micro Dr. Safety for Android (Consumer) versions below 3.0.1478 could allow an remote attacker to bypass the Same Origin Policy (SOP) and obtain sensitive information via crafted JavaScript code on vulnerable installations.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"18334","Ordinal":"2","NoteData":"2019-02-05","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"18334","Ordinal":"3","NoteData":"2019-02-05","Type":"Other","Title":"Modified"}]}}}