The intent: URL implementation in Opera before 18 on Android allows attackers to read local files by leveraging an interaction error, as demonstrated by reading stored cookies.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/91090 | vdb entry |
http://jvndb.jvn.jp/jvndb/JVNDB-2014-000014 | third party advisory |
http://www.securityfocus.com/bid/65391 | vdb entry |
http://blogs.opera.com/security/2014/01/security-changes-features-opera-19/ | vendor advisory |
http://jvn.jp/en/jp/JVN23256725/index.html | third party advisory |