Security flaws exposed in Dolphin, Mercury mobile browsers

Security flaws exposed in Dolphin, Mercury mobile browsers

A security researcher has discovered security problems in the Dolphin and Mercury mobile browsers.
Benjamin Watson, blogging under the name Rotlogix, revealed the existence of vulnerabilities within the Android-based mobile browsers. Last week, the security researcher said the flaws could lead to remote code execution or arbitrary read/write access.
Mobotap's Dolphin Browser for Android is a highly customisable browser for smartphones and mobile devices, including search bar tailoring and themes. Following Chrome and Firefox, the browser app is one of the most popular mobile browsers for the Android OS and boasts between 50 million and 100 million installations.
However, it is this customisation and the download and installation of a theme which may place users at risk.
According to Watson, when new themes are downloaded, the files are transferred over HTTP as a standard .zip file under the extension .dwp. Through the use of a simple script, the downloaded theme can be intercepted and injected with a modified, malicious theme, which in turn allows for an arbitrary write in the Dolphin data directory.
The .zip payload can then be crafted to exploit the unzipping process of the browser theme. The researcher found that a malicious library could be uploaded to overwrite the original browser library, libdolphin.so, paving the way for full remote code execution.
When the malicious theme is applied, "full blown code execution" is possible, according to the researcher.
Security flaws exposed in Dolphin, Mercury mobile browsers

The Mercury browser also captured the security researcher's attention, and was discovered to be vulnerable to arbitrary reading and writing of files in the browser's data directory. iLegendSoft's browser has been downloaded between 500,000 and 1,000,000 times.
Watson said the Wi-Fi transfer feature is fault, due to "an insecure Intent URI scheme implementation and a path traversal vulnerability within a custom web server" used to support the facility. The Wi-Fi transfer feature is used to share files online, but linking the aforementioned vulnerabilities together results in an attacker being granted arbitrary read/write access.
Watson recommends that in both cases users avoid downloading and applying new themes, and they should also consider using a different browser altogether until patches have been issued.
Source: http://www.zdnet.com/

COMMENTS

الاسم

business gallery games internet life style slider sports yechnology
false
rtl
item
Point Info: Security flaws exposed in Dolphin, Mercury mobile browsers
Security flaws exposed in Dolphin, Mercury mobile browsers
Security flaws exposed in Dolphin, Mercury mobile browsers
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgbQZBrgyJEZ5W2feIjUr9Hh3sF0fxRzzR1HqeoaL_GqvDk-FVytGZLzSDPM4l5qA0LmUZ3J6Mq_nvdKmmbwvWvMkuzer5Aov5VeGeO2-oh2nNX7YGO5jnUho4eQBI3W7w41Ze3w7LWUa0/s640/changeup-worm-imagecredsymantec.jpg
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgbQZBrgyJEZ5W2feIjUr9Hh3sF0fxRzzR1HqeoaL_GqvDk-FVytGZLzSDPM4l5qA0LmUZ3J6Mq_nvdKmmbwvWvMkuzer5Aov5VeGeO2-oh2nNX7YGO5jnUho4eQBI3W7w41Ze3w7LWUa0/s72-c/changeup-worm-imagecredsymantec.jpg
Point Info
https://point-3info.blogspot.com/2015/08/Security-flaws.html
https://point-3info.blogspot.com/
http://point-3info.blogspot.com/
http://point-3info.blogspot.com/2015/08/Security-flaws.html
true
8700007300930930388
UTF-8
Not found any posts VIEW ALL Readmore Reply Cancel reply Delete By Home PAGES POSTS View All RECOMMENDED FOR YOU LABEL ARCHIVE SEARCH ALL POSTS Not found any post match with your request Back Home Sunday Monday Tuesday Wednesday Thursday Friday Saturday Sun Mon Tue Wed Thu Fri Sat January February March April May June July August September October November December Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec just now 1 minute ago $$1$$ minutes ago 1 hour ago $$1$$ hours ago Yesterday $$1$$ days ago $$1$$ weeks ago more than 5 weeks ago Followers Follow THIS CONTENT IS PREMIUM Please share to unlock Copy All Code Select All Code All codes were copied to your clipboard Can not copy the codes / texts, please press [CTRL]+[C] (or CMD+C with Mac) to copy