Description
Opera for Android before 54.0.2669.49432 is vulnerable to a sandboxed cross-origin iframe bypass attack. By using a service working inside a sandboxed iframe it is possible to bypass the normal sandboxing attributes. This allows an attacker to make forced redirections without any user interaction from a third-party context.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-9387 | Opera for Android before 54.0.2669.49432 is vulnerable to a sandboxed cross-origin iframe bypass attack. By using a service working inside a sandboxed iframe it is possible to bypass the normal sandboxing attributes. This allows an attacker to make forced redirections without any user interaction from a third-party context. |
References
History
No history.
Status: PUBLISHED
Assigner: Opera
Published:
Updated: 2024-08-05T02:25:12.685Z
Reserved: 2019-12-13T00:00:00.000Z
Link: CVE-2019-19788
No data.
Status : Modified
Published: 2019-12-18T22:15:13.677
Modified: 2024-11-21T04:35:23.250
Link: CVE-2019-19788
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD