Security advisories

CVE-2021-44751: F‑Secure Internet Security Browser vulnerable to USSD attacks

Description

Vulnerability in the F‑Secure Internet Security Browser of F‑Secure Internet Security for Android could send unwanted USSD messages or perform unwanted calls.

STATUS: Fixed

RISK LEVEL: Medium

FIX: A fix has been released in the automatic update channel since 22nd, March 2022. No user action is required.

Affected products

  • F‑Secure Internet Security Browser for Android Version 18.5 and below

Platforms

  • All supported platforms for the affected products

More information

A vulnerability affecting F‑Secure Internet Security browser was discovered. A maliciously crafted website attached with USSD code in JavaScript or iFrame can trigger dialer application from F‑Secure browser which can be exploited by an attacker to send unwanted USSD messages or perform unwanted calls. In most modern Android OS, dialer application will require user inter­action, however, some older Android OS may not need user inter­action.

This issue was reported to F‑Secure through the Vulnerability Reward Program. No known exploit or attack has been seen in the wild.

Credits

F‑Secure Corporation would like to thank Kirtikumar Anandrao Ramchandani (@kirtikumar_a_r) for bringing this issue to our attention.

Date Issued: 2022-03-25