Sandbox Bypass Vulnerability in Opera for Android by Opera Software
CVE-2019-19788
5.5MEDIUM
Key Information:
- Vendor
- Opera Software As
- Status
- Opera For Android
- Vendor
- CVE Published:
- 18 December 2019
Summary
A vulnerability exists in Opera for Android versions prior to 54.0.2669.49432, which allows attackers to exploit a sandboxed cross-origin iframe bypass. This issue enables an attacker to manipulate a service operating within a sandboxed iframe, circumventing the typical sandboxing restrictions. Consequently, it may result in unauthorized forced redirections without user consent, posing significant security risks for users.
Affected Version(s)
Opera for Android Below 54.0.2669.49432
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved