CVE-2021-44748
Universal Cross-Site Scripting Vulnerability in F-Secure SAFE Browser for Android
More information
A vulnerability affecting WithSecure SAFE browser was discovered whereby browsers loads images automatically this vulnerability can be exploited remotely by an attacker to execute the JavaScript can be used to trigger universal cross-site scripting through the browser.
User interaction is required prior to exploitation, such as entering a malicious website to trigger the vulnerability.
This issue was reported to WithSecure through the Vulnerability Reward Program. No known exploit or attack has been seen in the wild.
Contributors
WithSecure Corporation would like to thank following person for bringing this issue to our attention.