Headline
CVE-2022-28869: CVE-2022-28869 | F-Secure
A vulnerability affecting F-Secure SAFE browser was discovered. A maliciously crafted website could make a phishing attack with address bar spoofing as the browser did not show full URL, such as port number.
Security Advisories
CVE-2022-28869: Address Bar Spoofing Vulnerability in F-Secure SAFE Browser for Android
Description
Incomplete display of URL could lead to address bar spoofing.
STATUS: Fixed
RISK LEVEL: Medium
FIX: A fix has been released in the automatic update channel since 13th April, 2022. No user action is required.
Affected Products
- F-Secure SAFE Browser for Android Version 18.6 and below
Platforms
- All supported platforms for the affected products
More Information
A vulnerability affecting F-Secure SAFE browser was discovered. A maliciously crafted website could make a phishing attack with address bar spoofing as the browser did not show full URL, such as port number.
This issue was reported to F-Secure through the Vulnerability Reward Program. No known exploit or attack has been seen in the wild.
Credits
F-Secure Corporation would like to thank Kirtikumar Anandrao Ramchandani for bringing this issue to our attention.