CVE-2019-12278
MEDIUMOpera through 53 on Android - Address Bar Spoofing via Unicode Right-to-Left Character Handling
Title source: llmDescription
Opera through 53 on Android allows Address Bar Spoofing. Characters from several languages are displayed in Right-to-Left order, due to mishandling of several Unicode characters. The rendering mechanism, in conjunction with the "first strong character" concept, may improperly operate on a numerical IP address or an alphabetic string, leading to a spoofed URL.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_misc
https://help.opera.com/en/latest/security-and-privacy/
Exploit, Third Party Advisory x_refsource_misc
https://medium.com/bugbountywriteup/opera-android-address-bar-spoofing-cve-2019-12278-9ffcfd6c508c
Scores
CVSS v3
4.3
EPSS
0.0035
EPSS Percentile
57.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Details
Status
published
Products (1)
opera/opera
52.1.2517.139570
Published
Mar 12, 2020
Tracked Since
Feb 18, 2026