5
CVSSv2

CVE-2018-18334

Published: 05/02/2019 Updated: 13/02/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

A vulnerability in the Private Browser of Trend Micro Dr. Safety for Android (Consumer) versions below 3.0.1478 could allow an remote malicious user to bypass the Same Origin Policy (SOP) and obtain sensitive information via crafted JavaScript code on vulnerable installations.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

trendmicro dr. safety

Recent Articles

Trend Micro pulls another app over security fears: This time, the Privacy Browser in the Dr Safety Android suite
The Register • Shaun Nichols in San Francisco • 12 Jun 2020

Some bugs prove very persistant Microsoft blocks Trend Micro code at center of driver 'cheatware' storm from Windows 10, rootkit detector product pulled from site

Trend Micro has pulled the Privacy Browser from its Dr Safety Android security suite following the discovery of a reoccurring flaw that could be abused to trick people into thinking malicious pages were legit. Security consultant Dhiraj Mishra discovered and privately reported the vulnerability to the software maker in April. Trend responded by pulling the app from its Android security suite. The bug, we're told, could be exploited by a miscreant to alter the address bar on pages viewed in the p...