VulnerabilityModified
CVE-2015-3830
The stock Android browser address bar in all Android operating systems suffers from Address Bar Spoofing, which allows remote attackers to trick a victim by displaying a malicious page for legitimate domain names.
MEDIUM 6.5EPSS 0.51%
Does this matter?
Lower severity and a low EPSS score (0.51%). Track it; it rarely justifies an emergency change on its own.
Description
The stock Android browser address bar in all Android operating systems suffers from Address Bar Spoofing, which allows remote attackers to trick a victim by displaying a malicious page for legitimate domain names.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
- EPSS
- 0.51% probability · 42th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- google/android
- Source
- security@android.com
References
- https://github.com/CHEF-KOCH/Android-Vulnerabilities-Overview/blob/master/2015.mdThird Party Advisory
- https://jsfiddle.net/dy4swq4o/Exploit, Third Party Advisory
- https://github.com/CHEF-KOCH/Android-Vulnerabilities-Overview/blob/master/2015.mdThird Party Advisory
- https://jsfiddle.net/dy4swq4o/Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.