SOP Bypass and Address Bar Spoofing in Yandex Browser for Android
CVE-2020-27969
7.3HIGH
What is CVE-2020-27969?
Yandex Browser for Android version 20.8.4 has a vulnerability that allows remote attackers to bypass the Same-Origin Policy (SOP), potentially leading to address bar spoofing. This security flaw could enable malicious actors to manipulate the browser's address bar, misleading users and compromising their security. It is essential for users of Yandex Browser to stay updated and apply necessary patches.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Yandex Browser for Android All versions prior to version 20.8.4.
References
CVSS V3.1
Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
