Safari Browser Hack Lets Attackers Spoof URLs
![]() |
| Safari Browser Hack Lets Attackers Spoof URLs |
Safari Browser Hack
Safari Browser Hack . A serious vulnerability found by some security researcher that can allow attackers to spoof website addresses in the Microsoft Edge web browser for Windows and Apple Safari for iOS.Phishing attacks are on the top in hacking and today its common in all and found in any latest hacking news as Microsoft has already update the Safari while monthly updates to get rid of such kinds of ridiculous things but the attacking is still intact and also has lots of vulnerabilities in browser, this is most dangerous for apple users as they search out many things on Safari and login to gmail as well.
Another security researcher in Pakistan name Rafay Baloch also track the serious vulnerability (CVE-2018-8383) in web browser he discovered that it is due to allowing JavaScript to update the page address in the URL bar while the page is loading.
How the URL Spoofing Vulnerability Works ?
One of the reason behind this spoofing is could be by replacing the malicious code or a URL that an attacker want when a page address is displayed in URL bar . Now another thing is if URL does not change still this kind of attack can works.Most targeted Websites:
By this attacker can spoof any URL of any most used websites like social media like Facebook , twitter as even the bank websites from users are performing daily transactions.Baloch created a proof-of-concept (PoC) page to test the vulnerability, and observed that both Microsoft Edge and
Apple Safari browsers "allowed javascript to update the address bar while the page was still loading."

No comments: