'Popular Android Browsers Dolphin and Mercury Are Vulnerable'

Advertisement
By Manish Singh | Updated: 24 August 2015 17:11 IST

Major security vulnerabilities have been found in Dolphin and Mercury Android browsers. Security enthusiast Rotologix has revealed zero-day flaws in the Web browsers, which if exploited, allows attackers to perform remote code execution.

The Dolphin and Mercury browsers are quite popular on Android, racking in over 100 million users. Specifically, the Dolphin remote code execution exploit allows an attacker to replace the browser's theme package with an infected counterpart.

Going further in, the exploit allows an attacker to modify the network traffic, which allows the person to modify the functionality of downloading and applying new themes to the browser. Once affected, a victim is only required to select, download, and apply a new Dolphin browser theme. The Dolphin browser hasn't been updated since July, suggesting that all users are likely affected by the zero-day vulnerability.

Advertisement

"An attacker with the ability to control the network traffic for users of the Dolphin browser for Android, can modify the functionality of downloading and applying new themes for the browser," Rotologix wrote in a blog post. "Through the exploitation of this functionality, an attacker can achieve an arbitrary file write, which can then be turned into code execution within the context of the browser on the user's device," he added.

Advertisement

Moving on, Rotologix says that Mercury browser for Android is affected with an insecure Intent URI scheme implementation and a path traversal vulnerability that provides support to the Wi-Fi Transfer feature. "Chaining these vulnerabilities together can allow a remote attacker to perform arbitrary reading and writing of files within the Mercury Browser's data directory," he added.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Android, Apps, Dolphin, Mercury, Security
Advertisement

Related Stories

Popular Mobile Brands
  1. Google Pixel 10a Listed on Retailer Websites With Pricing, Colour Options
  2. Oppo K14x 5G With 6,500mAh Battery Launched in India at This Price
  3. OnePlus Brings Valentine's Day Deals on Tablets, Audio Products: See Offers
  4. iQOO 15R Confirmed to Launch in India Soon With This 1.5K AMOLED Display
  5. The Next Flagship Snapdragon Chipset Could Make Phones More Expensive
  6. Nuuk Ren Pro Vacuum Review
  7. [Partner Content] OPPO Reno15 Series: AI Portrait Camera, Popout and First Compact Reno
  8. Nvidia GeForce Now for India Hands-On: Built to Impress
  9. NASA, SpaceX Delay ISS Mission Launch Due to Bad Weather
  1. NASA, SpaceX Delay ISS Mission Launch Due to Bad Weather
  2. Venus May Hide a Vast Underground Tunnel Formed by Ancient Volcanic Eruptions, Scientists Say
  3. Arc Raiders' Update 1.15.0 Adds New Event, Map Condition and Cosmetics
  4. Realme 16 Pro, Realme 15 Price in India to Be Hiked From February 11 Due to Rising Component Costs: Report
  5. Google Is Reportedly Bringing Personal Intelligence to NotebookLM
  6. Honor Magic 9 Series Tipped to Launch With Significant Battery Upgrade Over Magic 8 Models
  7. Databricks CEO Reportedly Highlights Existential Risk to SaaS Days After IT Market Crash
  8. iQOO Z11, iQOO Z11x Launch Appears Imminent as Both Handsets Visit China’s 3C Certification Database
  9. Google Pixel 10a Price, RAM and Storage Configurations Revealed via Retail Listings Ahead of February 18 Launch
  10. Anthropic Sues Anthropic? AI Startup’s India Ambitions Face Legal Challenge Over Brand Confusion: Report
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.