OSV 1.4.0 · unreviewed · 修改于 2022-01-04 08:01
发布时间
2021-12-17 08:00
GitHub 审查时间
—
NVD 发布时间
2021-12-16 19:15
源文件
advisories/unreviewed/2021/12/GHSA-75cm-2vvh-47g6/GHSA-75cm-2vvh-47g6.json
An URL Address bar spoofing vulnerability was discovered in Safe Browser for iOS. When user clicks on a specially crafted a malicious URL, if user does not carefully pay attention to url, user may be tricked to think content may be coming from a valid domain, while it comes from another. This is performed by using a very long username part of the url so that user cannot see the domain name. A remote attacker can leverage this to perform url address bar spoofing attack. The fix is, browser no longer shows the user name part in address bar.
该公告没有提供结构化的受影响软件包信息。