VYPR
Unrated severityNVD Advisory· Published Dec 10, 2021· Updated Aug 4, 2024

User interface Spoofing in F-Secure SAFE browser for Android

CVE-2021-40834

Description

A user interface overlay vulnerability was discovered in F-secure SAFE Browser for Android. When user click on a specially crafted seemingly legitimate URL SAFE browser goes into full screen and hides the user interface. A remote attacker can leverage this to perform spoofing attack.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

F-Secure SAFE Browser for Android has a UI overlay vulnerability allowing remote attackers to perform spoofing attacks when users click crafted URLs.

Vulnerability

A user interface overlay vulnerability exists in F-Secure SAFE Browser for Android [1]. When a user clicks a specially crafted URL that appears legitimate, the browser enters fullscreen mode and hides the user interface elements. This allows an attacker to spoof the browser chrome [1]. Affected versions include all releases prior to the fix; specific version numbers are not disclosed in the available references.

Exploitation

An attacker must craft a URL that appears benign to the victim [1]. Upon clicking the URL, the victim's SAFE Browser enters fullscreen mode and hides the address bar and other UI components [1]. The attacker can then display arbitrary content in place of the true interface, enabling spoofing of trusted sites [1]. No additional authentication or network position is required beyond delivering the crafted link to the user.

Impact

Successful exploitation allows the attacker to perform spoofing attacks [1]. The victim may be tricked into interacting with a fake interface, potentially leading to disclosure of sensitive information or installation of malicious content [1]. The impact is limited to UI spoofing; remote code execution is not achieved.

Mitigation

F-Secure has acknowledged the vulnerability and recommends users update to the latest version of SAFE Browser for Android [1]. The advisory lists related CVEs but does not specify the exact fixed version [1]. Users should ensure their app is up to date via the Google Play Store [1].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.