Address Bar Spoofing Bugs Found in Safari, Chrome for Android

Researchers have discovered address bar spoofing vulnerabilities in the Safari and Google Chrome for Android web browsers. Cybercriminals can exploit the bugs in phishing attacks. The flaw affecting Apple’s Safari was identified by researchers at UK-based security firm Deusen. The bug, for which experts created a simple proof-of-concept (PoC) webpage, affects the latest version of Safari on both OS X and iOS. The PoC from Deusen displays the URL “dailymail.co.uk” in the browser’s address bar for a webpage hosted on deusen.co.uk. This spoofing vulnerability can be very useful for phishing attacks. “The [PoC] code is very simple: webpage reloads every 10 milliseconds using the setInterval() function, just before the browser...

Continue reading
Ehack.org