F-Secure Safe Browser for iOS Address Bar Spoofing Vulnerability
BID:67506
Info
F-Secure Safe Browser for iOS Address Bar Spoofing Vulnerability
| Bugtraq ID: | 67506 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 19 2014 12:00AM |
| Updated: | May 19 2014 12:00AM |
| Credit: | Lukasz Pilorz |
| Vulnerable: |
F-Secure Safe Browser 0 |
| Not Vulnerable: |
F-Secure Safe Browser 2.50.201102 |
Discussion
F-Secure Safe Browser for iOS Address Bar Spoofing Vulnerability
F-Secure Safe Browser for iOS is prone to an address bar spoofing vulnerability.
An attacker can then display spoofed site contents to the user that seemingly originate from the trusted site. This allows a remote attacker to carry out phishing attacks. Other attacks may be possible.
F-Secure Safe Browser for iOS is prone to an address bar spoofing vulnerability.
An attacker can then display spoofed site contents to the user that seemingly originate from the trusted site. This allows a remote attacker to carry out phishing attacks. Other attacks may be possible.
Exploit / POC
F-Secure Safe Browser for iOS Address Bar Spoofing Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to follow a crafted URI.
To exploit this issue, an attacker must entice an unsuspecting user to follow a crafted URI.
Solution / Fix
F-Secure Safe Browser for iOS Address Bar Spoofing Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
F-Secure Safe Browser for iOS Address Bar Spoofing Vulnerability
References:
References: