Junglewise Threat Intelligence

CVE-2016-6908: Opera Browser for Android URL spoofing via RTL characters

CVE-2016-6908 · Severity: medium · CVSS 6.1 · Published 2017-01-26

Technologies: Opera Browser, Opera Software Opera. Vendors: Opera, Opera Software.

Executive brief

A vulnerability in the Opera browser for Android allows attackers to trick users into visiting malicious websites by misrepresenting the web address (URL). By using specific characters from languages like Arabic or Hebrew, an attacker can cause the address bar to display the URL in reverse order, making a fraudulent site appear legitimate. This can be used in phishing attacks to steal user credentials or sensitive information.

Technical details

Opera for Android 37.0.2192.105088 fails to properly enforce Left-To-Right (LTR) directionality in the omnibox when processing certain Unicode characters (e.g., U+FE70, U+0622). When a URL begins with an IP address or an RTL 'strong' character followed by neutral characters like '/' or '?', the browser may render the entire string in Right-To-Left (RTL) order. This allows an attacker to craft a URL that visually appears to belong to a trusted domain while actually pointing to a malicious IP or host. Exploitation requires the user to navigate to the attacker-controlled link.

Affected products

  • Opera Opera Browser 37.0.2192.105088

Timeline

  • 2017-01-26: advisory: NVD publication date

References

Related threats