
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2021-33595 is an address bar spoofing vulnerability discovered in F-Secure SAFE Browser for iOS. The vulnerability allows an attacker to show a legitimate URL in the address bar while loading content from a different domain, potentially misleading users about the authenticity of the website they are visiting (CERT-FR, CVE List).
The vulnerability exists due to inappropriate address handling in the browser that allows showing the legitimate URL in the address bar while loading content from a malicious domain. This makes users believe that the content is being served by a legitimate domain when it actually comes from an attacker-controlled site (CVE List).
The vulnerability could be exploited to conduct phishing attacks by making users believe they are interacting with a legitimate website while actually submitting their sensitive information to a malicious site. This creates a significant risk for credential theft and other forms of social engineering attacks (CERT-FR).
Users should update their F-Secure SAFE Browser to version 18.4.x or later which contains fixes for this vulnerability (CERT-FR).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."