Race Condition Vulnerability in Yandex Browser for Android
CVE-2017-7326

7.5HIGH

Key Information:

Vendor
CVE Published:
19 January 2018

What is CVE-2017-7326?

A race condition vulnerability exists in Yandex Browser for Android versions prior to 17.4.0.16. This flaw allows remote attackers to exploit memory corruption through specially crafted HTML pages, potentially leading to unauthorized access or manipulation of user data. Proper encapsulation and synchronization mechanisms are necessary to mitigate such risks, and users are advised to update their browsers to the latest version to protect against this vulnerability.

Affected Version(s)

Yandex Browser for Android All versions prior to version 17.4.0.16.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.