PT-2022-8037 · Opera · Opera Mini

Nikhil Mittal

·

Published

2022-12-26

·

Updated

2023-01-05

·

CVE-2018-16135

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Opera Mini version 47.1.2249.129326
Description The issue allows remote attackers to spoof the Location Permission dialog via a crafted web site. This can be achieved by accessing specific API Endpoints or by manipulating certain variables, although the specific details of these endpoints and variables are not provided. The general information about the issue suggests it is related to how the Opera Mini application handles location permissions, potentially allowing for unauthorized access or spoofing.
Recommendations For Opera Mini version 47.1.2249.129326, consider updating to a newer version that addresses this issue, as the current version allows for the spoofing of the Location Permission dialog. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2018-16135

Affected Products

Opera Mini