Safari, Edge Browsers Said to Be Vulnerable to Address Bar Spoofing Issue; Apple Reportedly Yet to Fix Bug

Advertisement
By Sumit Chakraborty | Updated: 12 September 2018 18:39 IST
Highlights
  • Safari and Edge spoofing exploit revealed
  • Microsoft had released a fix as part of August 14 'Patch Tuesday'
  • Apple is yet to patch spoofing vulnerability

URL bar spoofing allows website addresses to be spoofed in Safari for iOS and Microsoft's Edge browser

Photo Credit: Rafay Baloch

A security researcher claims to have discovered an issue that can leave URLs to be spoofed in Safari for iOS and Microsoft Edge browser for Windows 10. While Microsoft has fixed the bug, Apple is yet to release a fix. The new address bar spoofing attack (CVE-2018-8383) that has been found uses phishing techniques that can reportedly bypass basic indicators like URL, which are the first checks to determine if a particular site is fake. The vulnerability was first reported to both the companies on June 2, with the researcher issuing a 90-day deadline to issue a fix before publication. Last month, a reminder of the 90-day deadline was issued, and Microsoft released a fix as part of August 14 'Patch Tuesday'.

Researcher Rafay Baloch explains the vulnerability as a race condition that can enable an attacker to loading a legitimate webpage, resulting in the page's address to appear in the address bar, then rewriting the code for the body of the page to something dangerous without updating the URL at all, reports The Register. This essentially has the potential to enable an attacker to create fake login screens or other forms that could be used in extracting usernames, passwords, and other personal user data, while the users think they were on a legit page.

Advertisement

Baloch explains, "During my testing, it was observed that upon requesting data from a non-existent port the address was preserved and hence due to a race condition over a resource requested from non-existent port combined with the delay induced by setInterval function managed to trigger address bar spoofing." He adds, "It causes browser to preserve the address bar and to load the content from the spoofed page. The browser will however eventually load the resource, however the delay induced with setInterval function would be enough to trigger the address bar spoofing."

Proof-of-concept videos for both the Edge browser (v42.17134.1.0) and Safari (iOS 11.3.1) were posted by Baloch on his site. It is interesting to note that since both the browsers are closed-source, there is no clarity on why Edge and Safari would be affected by the same issue, while Chrome or Firefox remain unaffected. As mentioned, Microsoft has already fixed the bug, but Baloch says Apple will fix it in an upcoming update.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Samsung Galaxy A27 Spotted in Leaked Mint Colourway, Might Launch Soon
  2. Bitcoin Rebounds as Buyers Return Despite ETF Outflow Concerns
  3. Redmi Turbo 5 Confirmed to Launch in India With This Rear Camera Setup
  4. Vivo V70 Lite 5G Silently Launched in Select Markets With These Features
  5. Vivo X300 FE, iQOO 15R and More Discounted During Amazon Mega Deal Days Sale
  6. New Leak Shows Us What Apple's Foldable iPhone Might Look Like
  7. Samsung Galaxy S27 Pro's Battery May Match the One on the Galaxy S26 Ultra
  8. Infinix Hot 70 Pro India Launch Timeline, Key Specifications Leaked
  9. Infinix Smart 20 Launched in India With a 7.7mm Slim Body, Ultra Link Support
  1. WhatsApp Multi-Account Support on iOS Reportedly Rolling Out to More Users
  2. HTX Delists USD1 Stablecoin, Asks World Liberty Financial to Reverse Freeze on Exchange's Addresses
  3. Asus Dawn 7 Pro Series Launched With Up to 16-Inch 144Hz Display, AMD Ryzen AI 7 445 Chip: Price, Features
  4. Redmi Turbo 5 Confirmed to Launch in India With Identical Dual Rear Camera Setup as Chinese Variant
  5. OnePlus Turbo 6X Series Launch Date Announced Along With Key Specifications, Features
  6. WWDC 2026: Tim Cook’s Final Apple Keynote Marks the End of an Era
  7. Infinix Smart 20 Launched in India With MediaTek Helio G81 Ultimate SoC, Slim 7.7mm Profile: Price, Features
  8. Infinix Hot 70 Pro India Launch Timeline Leaked; Could Feature Dimensity 7100 Chip, 6,000mAh Battery
  9. Bitcoin Rebounds Above $62,000 as Buyers Return at Lower Prices Despite ETF Outflow Concerns
  10. Samsung Galaxy S26 FE WPC Database Listing Reveals Design, Qi2 Wireless Charging Support
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.