PT-2022-12222 · F Secure+1 · F-Secure Safe Browser+1
Published
2022-03-25
·
Updated
2022-04-04
·
CVE-2021-44751
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
F-Secure SAFE browser versions prior to March 22, 2022
Description
A maliciously crafted website with USSD code in JavaScript or iFrame can trigger the dialer application from the F-Secure browser, potentially allowing an attacker to send unwanted USSD messages or make unwanted calls. In most modern Android OS, the dialer application requires user interaction, but some older Android OS may not need user interaction.
Recommendations
For versions prior to March 22, 2022, consider disabling the dialer application trigger in the F-Secure browser until a patch is available. Restrict access to potentially malicious websites to minimize the risk of exploitation. As a temporary workaround, avoid using the F-Secure browser to access websites with USSD code in JavaScript or iFrame until the issue is resolved.
Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android Os
F-Secure Safe Browser