Address Bar Spoofing Vulnerability in Yandex Browser Lite for Android
CVE-2021-25254

8.2HIGH

Key Information:

Vendor

Yandex

Vendor
CVE Published:
21 May 2025

What is CVE-2021-25254?

The Yandex Browser Lite for Android prior to version 21.1.0 is susceptible to a vulnerability that permits remote attackers to spoof the address bar, potentially misleading users to malicious websites. This exploitation poses a significant risk as it can facilitate phishing attacks and compromise user data security. It is crucial for users to update to the latest version to mitigate this risk.

Affected Version(s)

Browser Lite Android 21.1.0

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kirtikumar Anandrao Ramchandani
.