Apple, Opera, and Yandex fix browser address bar spoofing bugs, but millions more still left vulnerable –
Summary
But even the browser’s anti-phishing features — often the last line of defense for a would-be phishing victim — aren’t perfect. Security researcher Rafay Baloch found several vulnerabilities in some of the most widely used mobile browsers — including Apple’s Safari, Opera, and Yandex — which if exploited would allow an attacker to trick the browser into displaying a different web address than the actual website that the user is on. The bugs worked by exploiting a weakness in the time it takes for a vulnerable browser to load a web page. Rapid7’s research director Tod Beardsley, who helped Baloch with disclosing the vulnerabilities to each browser maker, said address bar spoofing attacks put mobile users at particular risk. As a result, there’s not a lot of space available for security signals and sigils,” Beardsley told TechCrunch.