Multiple Address Bar Spoofing Vulnerability in F-Secure SAFE Browser for Android
Description
A vulnerability affecting F-Secure SAFE browser was discovered. An attacker can potentially exploit Javascript window.open functionality in SAFE Browser which could lead address bar spoofing attacks.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A vulnerability in F-Secure Internet Security Browser for Android allows address bar spoofing via JavaScript window.open, fixed in automatic updates since May 3, 2022.
Vulnerability
The vulnerability exists in F-Secure Internet Security Browser for Android version 19.0 and below. An attacker can exploit the JavaScript window.open functionality to spoof the address bar, potentially displaying a misleading URL to the user. [2]
Exploitation
An attacker would need to craft a malicious web page that uses the window.open method in a way that manipulates the address bar display. The user must visit the attacker-controlled page in the affected browser. No authentication or special network position is required beyond serving the page. [2]
Impact
Successful exploitation allows an attacker to perform address bar spoofing, which could trick the user into believing they are on a legitimate site, potentially leading to phishing or other social engineering attacks. The impact is limited to UI spoofing; no code execution or data theft is directly achieved. [2]
Mitigation
F-Secure released a fix via automatic update channel on May 3, 2022. Users with automatic updates enabled are protected without action. No manual patching is required. The vulnerability is not known to be exploited in the wild. [2]
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: 19.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.f-secure.com/en/home/support/security-advisoriesmitrex_refsource_MISC
- www.f-secure.com/en/home/support/security-advisories/cve-2022-28873mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.