PT-2022-12222 · F Secure+1 · F-Secure Safe Browser+1

Published

2022-03-25

·

Updated

2022-04-04

·

CVE-2021-44751

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions F-Secure SAFE browser versions prior to March 22, 2022
Description A maliciously crafted website with USSD code in JavaScript or iFrame can trigger the dialer application from the F-Secure browser, potentially allowing an attacker to send unwanted USSD messages or make unwanted calls. In most modern Android OS, the dialer application requires user interaction, but some older Android OS may not need user interaction.
Recommendations For versions prior to March 22, 2022, consider disabling the dialer application trigger in the F-Secure browser until a patch is available. Restrict access to potentially malicious websites to minimize the risk of exploitation. As a temporary workaround, avoid using the F-Secure browser to access websites with USSD code in JavaScript or iFrame until the issue is resolved.

Fix

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-44751

Affected Products

Android Os
F-Secure Safe Browser