7 Mobile Browsers Vulnerable to Address-Bar Spoofing

7 Mobile Browsers Vulnerable to Address-Bar Spoofing
Flaws allow attackers to manipulate URLs users see on their mobile devices, Rapid7 says

Security vendor Rapid7, in collaboration with independent researcher Rafay Baloch, this week disclosed details on new vulnerabilities in seven mobile browsers — including Safari and Opera — that allow attackers to spoof information showed in the browser's address bar.


The vulnerabilities are the latest examples of a common security weakness in software where the user interface can be tricked into displaying erroneous information or to make it appear as if the information comes from a trusted source. Phishers have routinely taken advantage of the user interface misrepresentation issue to trick users into navigating to malicious sites or to fool them into thinking they are on a trusted site when, in fact, they are not.


"The issues identified by Rafay Baloch's research are all unique issues per browser, but they all fall in the general vulnerability category described by CWE-451 — 'User Interface Misrepresentation of Critical Information,'" says Tod Beardsley, director of research at Rapid7.


Such vulnerabilities allow an attacker to control both the content of a website and the apparent source of the website, which can lead to very convincing-looking but malicious web pages.  According to Beardsley, the new vulnerabilities that Baloch discovered essentially give attackers a way to display false content when a mobile browser refreshes the address bar.


"Exploitation all comes down to, 'Javascript shenanigans'," Beardsley said in a blog this week. "By messing with the timing between page loads and when the browser gets a chance to refresh the address bar, an attacker ..

Support the originator by clicking the read the rest link below.