• Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
Tech News, Magazine & Review WordPress Theme 2017
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
Blog - Creative Collaboration
No Result
View All Result
Home Internet

Trend Micro drops secure browser app following security fears

June 13, 2020
Share on FacebookShare on Twitter

Trend Micro has made the decision to remove the Privacy Browser from its Dr Safety Android security suite after a reoccurring flaw was discovered in its software.

As reported by The Register, the vulnerability, which could be abused to trick users into believing that malicious web pages were legitimate, was first discovered by security consultant Dhiraj Mishra who responsibly reported it to the company back in April.

If exploited by an attacker, the bug could be used to alter the address bar on pages viewed in Trend Micro’s Privacy Browser. For example, a phishing page designed to steal users’ banking credentials could rewrite the URL bar to show the bank’s real domain name as opposed to the URL used by the attackers.

Privacy Browser

Mishra explained that the flaw would be fairly easy to exploit and that an attacker would have plenty of targets to choose from given its install base of 10m people in an interview with The Register, saying:

“To exploit such flaws remotely, an attacker would host a malicious JavaScript packet and if a user visits a page hosting that malicious code, a new window or tab can be opened with a fake URL. There is no way of determining if the URL is authentic or not due to which this could result in capturing sensitive information such as username passwords. Additionally, along with address bar spoofing, attackers could also spoof SSL which makes the attack more difficult to determine the authenticity of the URL.”

The vulnerability, tracked as CVE-2018-18334, has been confirmed by Trend Micro, though the company has decided to disable the browser outright instead of developing a patch for the flaw. Just by looking at the CVE assignment, you can see that the bug was first discovered in 2018 and the company has tried to deal with it in the past.

Back in January of last year, Trend Micro tried to patch the vulnerability but this year, Mishra was able to identify multiple address spoofing bugs of the same type that had not been fixed in the software. This explains why Trend Micro has now chosen to disable the Privacy Browser all together in its Dr Safety Android app.

  • Also check out our complete list of the best VPN services

Via The Register

Next Post

Android finally 11 removes 4GB video recoding cap

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

No Result
View All Result

Recent Posts

  • Ghost of Yōtei Legends: everything you need to know about the online co-op multiplayer mode
  • Nintendo Direct March 2026 livestream: Watch Super Mario Galaxy Movie Direct live
  • Pixel Watch SpO2 and skin temp vanish after March update
  • Newcastle United vs. Barcelona 2026 livestream: How to watch Champions League for free
  • Apple iPhone Fold part of ‘high-end’ Ultra line, report says

Recent Comments

    No Result
    View All Result

    Categories

    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi
    • Home
    • Shop
    • Privacy Policy
    • Terms and Conditions

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    No Result
    View All Result
    • Home
    • Blog
    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    Get more stuff like this
    in your inbox

    Subscribe to our mailing list and get interesting stuff and updates to your email inbox.

    Thank you for subscribing.

    Something went wrong.

    We respect your privacy and take protecting it seriously