Sandbox Bypass Vulnerability in Opera for Android by Opera Software
CVE-2019-19788

5.5MEDIUM

Key Information:

Vendor
Opera Software As
Status
Opera For Android
Vendor
CVE Published:
18 December 2019

Summary

A vulnerability exists in Opera for Android versions prior to 54.0.2669.49432, which allows attackers to exploit a sandboxed cross-origin iframe bypass. This issue enables an attacker to manipulate a service operating within a sandboxed iframe, circumventing the typical sandboxing restrictions. Consequently, it may result in unauthorized forced redirections without user consent, posing significant security risks for users.

Affected Version(s)

Opera for Android Below 54.0.2669.49432

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.