IDN Homograph Attack Vulnerability in Yandex Browser for Android
CVE-2021-25262

6.9MEDIUM

Key Information:

Vendor

Yandex

Status
Vendor
CVE Published:
21 May 2025

What is CVE-2021-25262?

Yandex Browser for Android versions before 21.3.0 is susceptible to a security flaw that allows attackers to exploit IDN homograph attacks. This vulnerability can be leveraged to create misleading domain names that appear legitimate, potentially leading users to malicious sites without their knowledge. It underscores the need for users to remain cautious while browsing and to update to the latest version of the browser to mitigate such threats.

Affected Version(s)

Browser Android 21.3.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kirtikumar Anandrao Ramchandani
.