Jump to content
Facebook Twitter Youtube

[Software] Apple, Opera and more aim to tackle address bar spoofing browser bug


Hossam Taibi
 Share

Recommended Posts

DegdtrwWP5WPU8vyFj83mM-320-80.jpg

 

Several well-known and po[CENSORED]r web browsers contain a vulnerability that makes them susceptible to phishing attacks. The bug allows threat actors to display a different address to the one that the victim is actually visiting.

The bugs were discovered by security researcher Rafay Baloch, who found vulnerabilities affecting Opera, Safari, Yandex and numerous others, largely affecting mobile devices. The security flaw is not as effective on desktop devices, where individuals can more easily view other indicators regarding a website’s legitimacy. On mobile screens, checking the address bar is the primary method of discerning whether a webpage is real or not.

 

The bug works by replacing the malicious web address with a reputable one of the attacker’s choosing in the time it takes for the webpage to load. In some of the examples given by Baloch, the security padlock was even displayed by the fake web address, further supporting its authenticity.

Still at risk

“It is pertinent to mention here that several mobile browsers with huge userbases do not even have a dedicated email for reporting security vulnerabilities, which discourages security researchers from reporting security vulnerabilities,” Baloch wrote on his blog. “Google Chrome and Firefox have a bug bounty program in which both desktop and mobile browsers are in-scope, whereas Microsoft’s bug bounty program is only limited to desktop versions. Apart from this, there is a small subset of mobile browsers incentivizing security researchers and bug bounty hunters for reporting vulnerabilities.”

The browser bar vulnerability emphasizes the need for online users to remain vigilant against phishing attacks. Always question whether a link is genuine or not before clicking to avoid being taken to a malicious website and then double-check to see if anything looks suspicious once the page has loaded. 

  • I love it 1
Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

WHO WE ARE?

CsBlackDevil Community [www.csblackdevil.com], a virtual world from May 1, 2012, which continues to grow in the gaming world. CSBD has over 70k members in continuous expansion, coming from different parts of the world.

 

 

Important Links