Vulnerability Description
The Dolphin Browser for Android 12.0.2 suffers from an insecure parsing implementation of the Intent URI scheme. This vulnerability could allow attackers to abuse this implementation through a malicious Intent URI, in order to invoke private Activities within the Dolphin Browser.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Changyou | Dolphin | 12.0.2 |
References
- https://github.com/VerSprite/research/blob/master/advisories/VS-2017-002.mdThird Party Advisory
- https://github.com/VerSprite/research/blob/master/advisories/VS-2017-002.mdThird Party Advisory
FAQ
What is CVE-2017-17553?
CVE-2017-17553 is a vulnerability with a CVSS score of 5.3 (MEDIUM). The Dolphin Browser for Android 12.0.2 suffers from an insecure parsing implementation of the Intent URI scheme. This vulnerability could allow attackers to abuse this implementation through a malicio...
How severe is CVE-2017-17553?
CVE-2017-17553 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-17553?
Check the references section above for vendor advisories and patch information. Affected products include: Changyou Dolphin.