{"id":101081,"date":"2020-10-21T08:03:04","date_gmt":"2020-10-21T04:03:04","guid":{"rendered":"https:\/\/phonezone.ru\/news\/apple-opera-and-yandex-fix-browser-address-bar-spoofing-bugs-but-millions-more-still-left-vulnerable\/"},"modified":"2020-10-21T08:03:04","modified_gmt":"2020-10-21T04:03:04","slug":"apple-opera-and-yandex-fix-browser-address-bar-spoofing-bugs-but-millions-more-still-left-vulnerable","status":"publish","type":"post","link":"https:\/\/phonezone.ru\/news\/apple-opera-and-yandex-fix-browser-address-bar-spoofing-bugs-but-millions-more-still-left-vulnerable\/","title":{"rendered":"Apple, Opera and Yandex fix browser address bar spoofing bugs, but millions more still left vulnerable"},"content":{"rendered":"<p>Year after year, phishing remains one of the most popular and effective ways for attackers to steal your passwords. As users, we\u2019re mostly trained to spot the telltale signs of a phishing site, but most of us rely on carefully examining the web address in the browser\u2019s address bar to make sure the site is legitimate.<br \/>\nBut even the browser\u2019s anti-phishing features \u2014 often the last line of defense for a would-be phishing victim \u2014 aren\u2019t perfect.<br \/>\nSecurity researcher Rafay Baloch found several vulnerabilities in some of the most widely used mobile browsers \u2014 including Apple\u2019s  Safari, Opera  and Yandex  \u2014 which if exploited would allow an attacker to trick the browser into displaying a different web address than the actual website that the user is on. These address bar spoofing bugs make it far easier for attackers to make their phishing pages look like legitimate websites, creating the perfect conditions for someone trying to steal passwords.<\/p>\n<p>Riot automatically educates your team about phishing<\/p>\n<p>The bugs worked by exploiting a weakness in the time it takes for a vulnerable browser to load a web page. Once a victim is tricked into opening a link from a phishing email or text message, the malicious web page uses code hidden on the page to effectively replace the malicious web address in the browser\u2019s address bar to any other web address that the attacker chooses.<br \/>\nIn at least one case, the vulnerable browser retained the green padlock icon, indicating that the malicious web page with a spoofed web address was legitimate \u2014 when it wasn\u2019t.<\/p>\n<p>An address bar spoofing bug in Opera Touch for iOS (left) and Bolt Browser (right). These spoofing bugs can make phishing emails look far more convincing. (Image: Rapid7\/supplied)<\/p>\n<p>Rapid7\u2019s research director Tod Beardsley, who helped Baloch with disclosing the vulnerabilities to each browser maker, said address bar spoofing attacks put mobile users at particular risk.<br \/>\n\u201cOn mobile, space is at an absolute premium, so every fraction of an inch counts. As a result, there\u2019s not a lot of space available for security signals and sigils,\u201d Beardsley told TechCrunch. \u201cWhile on a desktop browser, you can either look at the link you\u2019re on, mouse over a link to see where you\u2019re going or even click on the lock to get certificate details. These extra sources don\u2019t really exist on mobile, so the location bar not only tells the user what site they\u2019re on, it\u2019s expected to tell the user this unambiguously and with certainty. If you\u2019re on palpay.com instead of the expected paypal.com, you could notice this and know you\u2019re on a fake site before you type in your password.\u201d<br \/>\n\u201cSpoofing attacks like this make the location bar ambiguous, and thus, allow an attacker to generate some credence and trustworthiness to their fake site,\u201d he said.<br \/>\nBaloch and Beardsley said the browser makers responded with mixed results.<br \/>\nSo far, only Apple and Yandex pushed out fixes in September and October. Opera spokesperson Julia Szyndzielorz said the fixes for its Opera Touch and Opera Mini browsers are \u201cin gradual rollout.\u201d<br \/>\nBut the makers of UC Browser, Bolt Browser and RITS Browser \u2014 which collectively have more than 600 million device installs \u2014 did not respond to the researchers and left the vulnerabilities unpatched.<br \/>\nTechCrunch reached out to each browser maker but none provided a statement by the time of publication.<\/p>\n<p>A simple bug makes it easy to spoof Google search results into spreading misinformation<\/p>\n<p><a href=\"https:\/\/guce.techcrunch.com\/consent?brandType=nonEU&#038;done=https%3A%2F%2Ftechcrunch%2Ecom%2F2020%2F10%2F20%2Fapple%2Dopera%2Dfix%2Dbrowser%2Daddress%2Dbar%2Dspoofing%2F&#038;gcrumb=LGYBHAU=\">Apple, Opera and Yandex fix browser address bar spoofing bugs, but millions more still left vulnerable<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Year after year, phishing remains one of the most popular and effective ways for attackers to steal your passwords. As users, we\u2019re mostly trained to spot the telltale signs of a phishing site, but most of us rely on carefully examining the web address in the browser\u2019s address bar to make sure the site is [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[5147,9226,5114,9227,9228,9229,5180,9230,9231],"tags":[9234,9232,9235,9233],"class_list":["post-101081","post","type-post","status-publish","format-standard","hentry","category-apple","category-browser-security","category-mobile","category-opera","category-phishing","category-safari","category-security","category-web-browsers","category-yandex","tag-bolt-browser","tag-julia-szyndzielorz","tag-opera-touch","tag-tod-beardsley"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Apple, Opera and Yandex fix browser address bar spoofing bugs, but millions more still left vulnerable - \u041d\u043e\u0432\u043e\u0441\u0442\u0438 \u043c\u043e\u0431\u0438\u043b\u044c\u043d\u044b\u0445 \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u0439<\/title>\n<meta name=\"description\" content=\"Year after year, phishing remains one of the most popular and effective ways for attackers to steal your passwords. As users, we\u2019re mostly trained to spot\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/phonezone.ru\/news\/apple-opera-and-yandex-fix-browser-address-bar-spoofing-bugs-but-millions-more-still-left-vulnerable\/\" \/>\n<meta property=\"og:locale\" content=\"ru_RU\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Apple, Opera and Yandex fix browser address bar spoofing bugs, but millions more still left vulnerable - \u041d\u043e\u0432\u043e\u0441\u0442\u0438 \u043c\u043e\u0431\u0438\u043b\u044c\u043d\u044b\u0445 \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u0439\" \/>\n<meta property=\"og:description\" content=\"Year after year, phishing remains one of the most popular and effective ways for attackers to steal your passwords. As users, we\u2019re mostly trained to spot\" \/>\n<meta property=\"og:url\" content=\"https:\/\/phonezone.ru\/news\/apple-opera-and-yandex-fix-browser-address-bar-spoofing-bugs-but-millions-more-still-left-vulnerable\/\" \/>\n<meta property=\"og:site_name\" content=\"\u041d\u043e\u0432\u043e\u0441\u0442\u0438 \u043c\u043e\u0431\u0438\u043b\u044c\u043d\u044b\u0445 \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u0439\" \/>\n<meta property=\"article:published_time\" content=\"2020-10-21T04:03:04+00:00\" \/>\n<meta name=\"author\" content=\"Mobile news chief editor\" \/>\n<meta name=\"twitter:label1\" content=\"\u041d\u0430\u043f\u0438\u0441\u0430\u043d\u043e \u0430\u0432\u0442\u043e\u0440\u043e\u043c\" \/>\n\t<meta name=\"twitter:data1\" content=\"Mobile news chief editor\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u041f\u0440\u0438\u043c\u0435\u0440\u043d\u043e\u0435 \u0432\u0440\u0435\u043c\u044f \u0434\u043b\u044f \u0447\u0442\u0435\u043d\u0438\u044f\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 \u043c\u0438\u043d\u0443\u0442\u044b\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/phonezone.ru\\\/news\\\/apple-opera-and-yandex-fix-browser-address-bar-spoofing-bugs-but-millions-more-still-left-vulnerable\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/phonezone.ru\\\/news\\\/apple-opera-and-yandex-fix-browser-address-bar-spoofing-bugs-but-millions-more-still-left-vulnerable\\\/\"},\"author\":{\"name\":\"Mobile news chief editor\",\"@id\":\"https:\\\/\\\/phonezone.ru\\\/news\\\/#\\\/schema\\\/person\\\/659775c2c0130cf3d639e6e8c0aede94\"},\"headline\":\"Apple, Opera and Yandex fix browser address bar spoofing bugs, but millions more still left vulnerable\",\"datePublished\":\"2020-10-21T04:03:04+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/phonezone.ru\\\/news\\\/apple-opera-and-yandex-fix-browser-address-bar-spoofing-bugs-but-millions-more-still-left-vulnerable\\\/\"},\"wordCount\":617,\"commentCount\":0,\"keywords\":[\"Bolt Browser\",\"Julia Szyndzielorz\",\"Opera Touch\",\"Tod Beardsley\"],\"articleSection\":[\"Apple\",\"browser security\",\"Mobile\",\"Opera\",\"phishing\",\"safari\",\"Security\",\"Web browsers\",\"Yandex\"],\"inLanguage\":\"ru-RU\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/phonezone.ru\\\/news\\\/apple-opera-and-yandex-fix-browser-address-bar-spoofing-bugs-but-millions-more-still-left-vulnerable\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/phonezone.ru\\\/news\\\/apple-opera-and-yandex-fix-browser-address-bar-spoofing-bugs-but-millions-more-still-left-vulnerable\\\/\",\"url\":\"https:\\\/\\\/phonezone.ru\\\/news\\\/apple-opera-and-yandex-fix-browser-address-bar-spoofing-bugs-but-millions-more-still-left-vulnerable\\\/\",\"name\":\"Apple, Opera and Yandex fix browser address bar spoofing bugs, but millions more still left vulnerable - \u041d\u043e\u0432\u043e\u0441\u0442\u0438 \u043c\u043e\u0431\u0438\u043b\u044c\u043d\u044b\u0445 \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u0439\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/phonezone.ru\\\/news\\\/#website\"},\"datePublished\":\"2020-10-21T04:03:04+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/phonezone.ru\\\/news\\\/#\\\/schema\\\/person\\\/659775c2c0130cf3d639e6e8c0aede94\"},\"description\":\"Year after year, phishing remains one of the most popular and effective ways for attackers to steal your passwords. As users, we\u2019re mostly trained to spot\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/phonezone.ru\\\/news\\\/apple-opera-and-yandex-fix-browser-address-bar-spoofing-bugs-but-millions-more-still-left-vulnerable\\\/#breadcrumb\"},\"inLanguage\":\"ru-RU\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/phonezone.ru\\\/news\\\/apple-opera-and-yandex-fix-browser-address-bar-spoofing-bugs-but-millions-more-still-left-vulnerable\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/phonezone.ru\\\/news\\\/apple-opera-and-yandex-fix-browser-address-bar-spoofing-bugs-but-millions-more-still-left-vulnerable\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\u0413\u043b\u0430\u0432\u043d\u043e\u0435 \u043c\u0435\u043d\u044e\",\"item\":\"https:\\\/\\\/phonezone.ru\\\/news\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Apple, Opera and Yandex fix browser address bar spoofing bugs, but millions more still left vulnerable\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/phonezone.ru\\\/news\\\/#website\",\"url\":\"https:\\\/\\\/phonezone.ru\\\/news\\\/\",\"name\":\"\u041d\u043e\u0432\u043e\u0441\u0442\u0438 \u043c\u043e\u0431\u0438\u043b\u044c\u043d\u044b\u0445 \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u0439\",\"description\":\"\u041d\u043e\u0432\u043e\u0441\u0442\u043d\u0430\u044f \u043b\u0435\u043d\u0442\u0430: \u043c\u043e\u0431\u0438\u043b\u044c\u043d\u044b\u0435 \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u0438\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/phonezone.ru\\\/news\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"ru-RU\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/phonezone.ru\\\/news\\\/#\\\/schema\\\/person\\\/659775c2c0130cf3d639e6e8c0aede94\",\"name\":\"Mobile news chief editor\",\"url\":\"https:\\\/\\\/phonezone.ru\\\/news\\\/author\\\/admin\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Apple, Opera and Yandex fix browser address bar spoofing bugs, but millions more still left vulnerable - \u041d\u043e\u0432\u043e\u0441\u0442\u0438 \u043c\u043e\u0431\u0438\u043b\u044c\u043d\u044b\u0445 \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u0439","description":"Year after year, phishing remains one of the most popular and effective ways for attackers to steal your passwords. As users, we\u2019re mostly trained to spot","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/phonezone.ru\/news\/apple-opera-and-yandex-fix-browser-address-bar-spoofing-bugs-but-millions-more-still-left-vulnerable\/","og_locale":"ru_RU","og_type":"article","og_title":"Apple, Opera and Yandex fix browser address bar spoofing bugs, but millions more still left vulnerable - \u041d\u043e\u0432\u043e\u0441\u0442\u0438 \u043c\u043e\u0431\u0438\u043b\u044c\u043d\u044b\u0445 \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u0439","og_description":"Year after year, phishing remains one of the most popular and effective ways for attackers to steal your passwords. As users, we\u2019re mostly trained to spot","og_url":"https:\/\/phonezone.ru\/news\/apple-opera-and-yandex-fix-browser-address-bar-spoofing-bugs-but-millions-more-still-left-vulnerable\/","og_site_name":"\u041d\u043e\u0432\u043e\u0441\u0442\u0438 \u043c\u043e\u0431\u0438\u043b\u044c\u043d\u044b\u0445 \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u0439","article_published_time":"2020-10-21T04:03:04+00:00","author":"Mobile news chief editor","twitter_misc":{"\u041d\u0430\u043f\u0438\u0441\u0430\u043d\u043e \u0430\u0432\u0442\u043e\u0440\u043e\u043c":"Mobile news chief editor","\u041f\u0440\u0438\u043c\u0435\u0440\u043d\u043e\u0435 \u0432\u0440\u0435\u043c\u044f \u0434\u043b\u044f \u0447\u0442\u0435\u043d\u0438\u044f":"3 \u043c\u0438\u043d\u0443\u0442\u044b"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/phonezone.ru\/news\/apple-opera-and-yandex-fix-browser-address-bar-spoofing-bugs-but-millions-more-still-left-vulnerable\/#article","isPartOf":{"@id":"https:\/\/phonezone.ru\/news\/apple-opera-and-yandex-fix-browser-address-bar-spoofing-bugs-but-millions-more-still-left-vulnerable\/"},"author":{"name":"Mobile news chief editor","@id":"https:\/\/phonezone.ru\/news\/#\/schema\/person\/659775c2c0130cf3d639e6e8c0aede94"},"headline":"Apple, Opera and Yandex fix browser address bar spoofing bugs, but millions more still left vulnerable","datePublished":"2020-10-21T04:03:04+00:00","mainEntityOfPage":{"@id":"https:\/\/phonezone.ru\/news\/apple-opera-and-yandex-fix-browser-address-bar-spoofing-bugs-but-millions-more-still-left-vulnerable\/"},"wordCount":617,"commentCount":0,"keywords":["Bolt Browser","Julia Szyndzielorz","Opera Touch","Tod Beardsley"],"articleSection":["Apple","browser security","Mobile","Opera","phishing","safari","Security","Web browsers","Yandex"],"inLanguage":"ru-RU","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/phonezone.ru\/news\/apple-opera-and-yandex-fix-browser-address-bar-spoofing-bugs-but-millions-more-still-left-vulnerable\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/phonezone.ru\/news\/apple-opera-and-yandex-fix-browser-address-bar-spoofing-bugs-but-millions-more-still-left-vulnerable\/","url":"https:\/\/phonezone.ru\/news\/apple-opera-and-yandex-fix-browser-address-bar-spoofing-bugs-but-millions-more-still-left-vulnerable\/","name":"Apple, Opera and Yandex fix browser address bar spoofing bugs, but millions more still left vulnerable - \u041d\u043e\u0432\u043e\u0441\u0442\u0438 \u043c\u043e\u0431\u0438\u043b\u044c\u043d\u044b\u0445 \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u0439","isPartOf":{"@id":"https:\/\/phonezone.ru\/news\/#website"},"datePublished":"2020-10-21T04:03:04+00:00","author":{"@id":"https:\/\/phonezone.ru\/news\/#\/schema\/person\/659775c2c0130cf3d639e6e8c0aede94"},"description":"Year after year, phishing remains one of the most popular and effective ways for attackers to steal your passwords. As users, we\u2019re mostly trained to spot","breadcrumb":{"@id":"https:\/\/phonezone.ru\/news\/apple-opera-and-yandex-fix-browser-address-bar-spoofing-bugs-but-millions-more-still-left-vulnerable\/#breadcrumb"},"inLanguage":"ru-RU","potentialAction":[{"@type":"ReadAction","target":["https:\/\/phonezone.ru\/news\/apple-opera-and-yandex-fix-browser-address-bar-spoofing-bugs-but-millions-more-still-left-vulnerable\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/phonezone.ru\/news\/apple-opera-and-yandex-fix-browser-address-bar-spoofing-bugs-but-millions-more-still-left-vulnerable\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u0413\u043b\u0430\u0432\u043d\u043e\u0435 \u043c\u0435\u043d\u044e","item":"https:\/\/phonezone.ru\/news\/"},{"@type":"ListItem","position":2,"name":"Apple, Opera and Yandex fix browser address bar spoofing bugs, but millions more still left vulnerable"}]},{"@type":"WebSite","@id":"https:\/\/phonezone.ru\/news\/#website","url":"https:\/\/phonezone.ru\/news\/","name":"\u041d\u043e\u0432\u043e\u0441\u0442\u0438 \u043c\u043e\u0431\u0438\u043b\u044c\u043d\u044b\u0445 \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u0439","description":"\u041d\u043e\u0432\u043e\u0441\u0442\u043d\u0430\u044f \u043b\u0435\u043d\u0442\u0430: \u043c\u043e\u0431\u0438\u043b\u044c\u043d\u044b\u0435 \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u0438","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/phonezone.ru\/news\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"ru-RU"},{"@type":"Person","@id":"https:\/\/phonezone.ru\/news\/#\/schema\/person\/659775c2c0130cf3d639e6e8c0aede94","name":"Mobile news chief editor","url":"https:\/\/phonezone.ru\/news\/author\/admin\/"}]}},"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/phonezone.ru\/news\/wp-json\/wp\/v2\/posts\/101081","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/phonezone.ru\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/phonezone.ru\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/phonezone.ru\/news\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/phonezone.ru\/news\/wp-json\/wp\/v2\/comments?post=101081"}],"version-history":[{"count":0,"href":"https:\/\/phonezone.ru\/news\/wp-json\/wp\/v2\/posts\/101081\/revisions"}],"wp:attachment":[{"href":"https:\/\/phonezone.ru\/news\/wp-json\/wp\/v2\/media?parent=101081"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/phonezone.ru\/news\/wp-json\/wp\/v2\/categories?post=101081"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/phonezone.ru\/news\/wp-json\/wp\/v2\/tags?post=101081"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}