'Popular Android Browsers Dolphin and Mercury Are Vulnerable'

Advertisement
By Manish Singh | Updated: 24 August 2015 17:11 IST

Major security vulnerabilities have been found in Dolphin and Mercury Android browsers. Security enthusiast Rotologix has revealed zero-day flaws in the Web browsers, which if exploited, allows attackers to perform remote code execution.

The Dolphin and Mercury browsers are quite popular on Android, racking in over 100 million users. Specifically, the Dolphin remote code execution exploit allows an attacker to replace the browser's theme package with an infected counterpart.

Going further in, the exploit allows an attacker to modify the network traffic, which allows the person to modify the functionality of downloading and applying new themes to the browser. Once affected, a victim is only required to select, download, and apply a new Dolphin browser theme. The Dolphin browser hasn't been updated since July, suggesting that all users are likely affected by the zero-day vulnerability.

Advertisement

"An attacker with the ability to control the network traffic for users of the Dolphin browser for Android, can modify the functionality of downloading and applying new themes for the browser," Rotologix wrote in a blog post. "Through the exploitation of this functionality, an attacker can achieve an arbitrary file write, which can then be turned into code execution within the context of the browser on the user's device," he added.

Advertisement

Moving on, Rotologix says that Mercury browser for Android is affected with an insecure Intent URI scheme implementation and a path traversal vulnerability that provides support to the Wi-Fi Transfer feature. "Chaining these vulnerabilities together can allow a remote attacker to perform arbitrary reading and writing of files within the Mercury Browser's data directory," he added.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Android, Apps, Dolphin, Mercury, Security
Advertisement

Related Stories

Popular Mobile Brands
  1. Cloudflare Is Down Again For the Second Time in Weeks: See Affected Sites
  2. ACT Fibernet Launches New Broadband Plans With Free OTT Subscriptions
  3. Motorola Edge 70 With Pantone's 2026 Colour, Swarovski Crystals Launched
  4. HMD 101, HMD 100 With Built-In Radio Launched in India at These Prices
  5. Nothing Phone 3a Lite Goes on Sale in India at This Price
  6. Instamart to Provide 10-Minute Delivery of Samsung Galaxy Devices
  7. Here's What India Searched For the Most on Google in 2025
  8. Realme 16 Pro+ 5G New Leak Reveals Storage and Colour Variants
  9. Flipkart Buy Buy 2025 Sale: Nothing Phone 3, Phone 3a Deals Revealed
  10. Realme Says It Will Launch Two New Narzo Smartphones in India Soon
  1. Google’s Year in Search 2025: Top Trending Topics in India—From Gemini to Squid Games
  2. Vivo S50 Colour Options, Key Features Surface Online; Could Launch in India as Vivo V70
  3. CFTC Clears Path for Spot Crypto Trading on Regulated Platforms for the First Time
  4. Realme 16 Pro+ 5G Colour Options, Memory Configurations Leaked Again; Tipped to Launch With 7,000mAh Battery
  5. Cloudflare Outage Blocks Access to Several Websites Including BookMyShow, SpaceX, Coinbase
  6. Samsung Galaxy S26 Series to Offer Built-In Support for Company's 25W Magnetic Qi2 Charger: Report
  7. Airtel Discontinues Two Prepaid Recharge Packs in India With Data Benefits, Free Airtel Xtreme Play Subscription
  8. Samsung Galaxy Phones, Devices Are Now Available via Instamart With 10-Minute Instant Delivery
  9. NotebookLM App Gets an In-Built Camera, Lets Users Upload Images as a Source
  10. HMD 101 Launched in India With 1,000mAh Battery, Auto Call Recording Alongside HMD 100: Price, Features
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.