A security bypass vulnerability exists in Symantec Norton Mobile Security for Android before 3.16, which could let a malicious user conduct a man-in-the-middle via specially crafted JavaScript to add arbitrary URLs to the URL whitelist.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1037225 | vdb entry third party advisory |
http://www.securityfocus.com/bid/93901 | vdb entry third party advisory |
https://support.symantec.com/us/en/article.symsa1384.html | vendor advisory |