Universal Cross-Site Scripting Vulnerability in F-Secure SAFE Browser for Android

More information

A vulnerability affecting WithSecure SAFE browser was discovered whereby browsers loads images automatically this vulnerability can be exploited remotely by an attacker to execute the JavaScript can be used to trigger universal cross-site scripting through the browser.

User interaction is required prior to exploitation, such as entering a malicious website to trigger the vulnerability. 

This issue was reported to WithSecure through the Vulnerability Reward Program. No known exploit or attack has been seen in the wild.


WithSecure Corporation would like to thank following person for bringing this issue to our attention.

Kirtikumar Anandrao Ramchandani


  • Vulnerabilities in the browser of WithSecure SAFE for Android could allow execution of JavaScript.
  • Status

  • Fixed
  • Risk level

  • Medium
  • Fix

  • A fix has been released in the automatic update channel since 18 February 2022. No user action is required if automatic update is enabled.
  • Affected products

  • WithSecure SAFE Browser for Android Version 18.5
  • Platforms

  • All supported platforms for the affected products.
  • Date issued

  • 3/3/2022
  • Security advisories
  • 2021
  • Medium