Android Browser Certificate Spoofing Vulnerability
Last Update Date:
28 Dec 2011 15:02
Release Date:
28 Dec 2011
5503
Views
RISK: Medium Risk
TYPE: Operating Systems - Mobile & Apps
A vulnerability has been identified in Android, which can be exploited by malicious people to conduct spoofing attacks.
The vulnerability is caused due to Browser displaying wrong certificate information, which can be exploited to trick a user into believing to be connected to a trusted site by including the trusted site in an iframe.
Impact
- Spoofing
System / Technologies affected
- Android 2.x
- Android 3.x
Solutions
- Do not rely on the displayed certificate information.
Vulnerability Identifier
- No CVE information is available
Source
Related Link
Share with