PT-2021-15417 · Opera · Opera Mini For Android

Published

2021-01-11

·

Updated

2021-01-20

·

CVE-2021-23253

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Opera Mini for Android versions prior to 53.1
Description The issue allows a malicious attacker to craft a URL with a long domain name. For example, www.safe.opera.com.attacker.com can be used to deceive users. Since the URL is left-aligned in the address field, the user will only see the front part, such as www.safe.opera.com…. The exact amount visible depends on the phone screen size, but the attacker can craft different domains to target various phones.
Recommendations For Opera Mini for Android versions prior to 53.1, update to version 53.1 or later, which displays long URLs with the top-level domain label aligned to the right of the address field, mitigating the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-23253

Affected Products

Opera Mini For Android