Universal Cross-Site Scripting Vulnerability in WithSecure SAFE Browser Protection for Android

More information

A vulnerability affecting WithSecure SAFE browser protection was discovered improper URL handling can be triggered to cause universal cross-site scripting through browsing protection in a SAFE web browser. User interaction is required prior to exploitation. A successful exploitation may lead to arbitrary code execution.

This issue was reported to WithSecure through the Vulnerability Reward Program. No known exploit or attack has been seen in the wild.


WithSecure Corporation would like to thank following person for bringing this issue to our attention.

Kirtikumar Anandrao Ramchandani


  • Vulnerabilities in the browser protection of WithSecure SAFE for Android could allow remote attacker to steal user's sessions cookie.
  • Status

  • Fixed
  • Risk level

  • Medium
  • Fix

  • A fix has been released in the automatic update channel since 18 February 2022. No user action is required if automatic update is enabled.
  • Affected products

  • WithSecure SAFE Browser for Android Version 18.5
  • Platforms

  • All supported platforms for the affected products.
  • Date issued

  • 3/3/2022
  • Security advisories
  • 2021
  • Medium