Vulnerability Description
Opera Mini for Android allows attackers to bypass intended restrictions on .apk file download/installation via an RTLO (aka Right to Left Override) approach, as demonstrated by misinterpretation of malicious%E2%80%AEtxt.apk as maliciouskpa.txt. This affects 44.1.2254.142553, 44.1.2254.142659, and 44.1.2254.143214.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Opera | Mini | 44.1.2254.142553 |
References
- http://firstsight.me/2019/10/illegal-rendered-at-download-feature-in-several-appExploitThird Party Advisory
- https://medium.com/%40YoKoKho/illegal-rendered-at-download-feature-in-opera-mini
- http://firstsight.me/2019/10/illegal-rendered-at-download-feature-in-several-appExploitThird Party Advisory
- https://medium.com/%40YoKoKho/illegal-rendered-at-download-feature-in-opera-mini
FAQ
What is CVE-2019-18624?
CVE-2019-18624 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Opera Mini for Android allows attackers to bypass intended restrictions on .apk file download/installation via an RTLO (aka Right to Left Override) approach, as demonstrated by misinterpretation of ma...
How severe is CVE-2019-18624?
CVE-2019-18624 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-18624?
Check the references section above for vendor advisories and patch information. Affected products include: Opera Mini.