Flaw in Outlook for Android Allows for Data Theft
#1
Quote:A vulnerability recently addressed in Outlook for Android allows an attacker to steal information from the affected device.
 
The vulnerability, Microsoft reveals, resides in the manner in which Outlook for Android parses specifically crafted email messages. To exploit the flaw, an authenticated attacker needs to send a specially crafted email message to the victim.
 
“The attacker who successfully exploited this vulnerability could then perform cross-site scripting attacks on the affected systems and run scripts in the security context of the current user,” the software giant explains in an advisory.
Tracked as CVE-2019-1105, the vulnerability was addressed last week “by correcting how Outlook for Android parses specially crafted email messages.”
 
F5 Networks security researcher Bryan Appleby, who reported the flaw to Microsoft, explains that the issue begins with the ability to embed an iframe into the email message.
JavaScript within the code would have no restrictions in Outlook on Android, being able to access cookies, tokens, and even some emails, which could also be sent back to a remote attacker.

SOURCE: https://www.securityweek.com/flaw-outloo...data-theft
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
AMD prepares Linux support for new Low P...
AMD Linux patch ad...harlan4096 — 07:16
Opera 149.0.7827.197
Dear Opera Users! ...harlan4096 — 07:14
Privazer 4.0.124.1 (28 June 2026)
v4.0.124.1 (28 Jun...harlan4096 — 07:13
GlassWire 3.9.1102 - (June 29, 2026)
Version 3.9.1102 -...harlan4096 — 07:12
AMD Radeon Software Adrenalin 26.6.4 dri...
AMD Radeon Software...harlan4096 — 07:10

[-]
Birthdays
Today's Birthdays
avatar (43)uapedDow
avatar (47)suiscced
avatar (48)Angarpaf
avatar (41)clarissalo60
Upcoming Birthdays
avatar (47)dapedDow
avatar (49)TromPerl
avatar (46)RidgeDimb
avatar (37)ipumaqar
avatar (51)tanliorsPeri
avatar (43)lapedDow
avatar (49)rituabew
avatar (37)omyjul
avatar (41)papedDow
avatar (50)ArnoldFum
avatar (38)yfaza
avatar (49)Kevensi
avatar (48)ConradRoand
avatar (39)boineDon
avatar (51)spoofTum
avatar (50)WillieVot
avatar (40)Grompelbawn
avatar (41)vkseogaF
avatar (37)usogy
avatar (41)optsaZes
avatar (40)RaymondViata
avatar (40)ywixazok
avatar (38)ixoqe
avatar (56)Step 1
avatar (36)pa.OpenTran

[-]
Online Staff
There are no staff members currently online.

>