Loading HuntDB...

Webview address bar spoofing in LINE client for iOS

Low
L
LY Corporation
Submitted None

Team Summary

Official summary from LY Corporation

When navigation to an invalid hostname occurs, the address bar is updated even though the navigation is cancelled. Due to this incorrect timing of updating the address bar and applying URL normalization, it can be recognized as a different hostname from the actual hostname. As a result, attacker may deceive the user to be browsing a legitimate site when the in-app browser is actually on a phishing site.

Reported by reinforchu

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Phishing