SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-18330

An Address Bar Spoofing vulnerability in Trend Micro Dr.

MEDIUM 6.5EPSS 0.95%

Does this matter?

Lower severity and a low EPSS score (0.95%). Track it; it rarely justifies an emergency change on its own.

Description

An Address Bar Spoofing vulnerability in Trend Micro Dr. Safety for Android (Consumer) versions 3.0.1324 and below could allow an attacker to potentially trick a victim into visiting a malicious URL using address bar spoofing on the Private Browser of the app on vulnerable installations.

CVSS 3.0
6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
EPSS
0.95% probability · 59th percentile
CISA KEV
Not listed
Affected
trendmicro/dr. safety
Source
security@trendmicro.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.