Skip to main content

Android Browser Certificate Spoofing Vulnerability

Last Update Date: 28 Dec 2011 15:02 Release Date: 28 Dec 2011 4745 Views

RISK: Medium Risk

TYPE: Operating Systems - Mobile & Apps

TYPE: Mobile & Apps

A vulnerability has been identified in Android, which can be exploited by malicious people to conduct spoofing attacks.

The vulnerability is caused due to Browser displaying wrong certificate information, which can be exploited to trick a user into believing to be connected to a trusted site by including the trusted site in an iframe.
 


Impact

  • Spoofing

System / Technologies affected

  • Android 2.x
  • Android 3.x

Solutions

  • Do not rely on the displayed certificate information.

Vulnerability Identifier

  • No CVE information is available

Source


Related Link