- Advertisement -

Critical security vulnerability discovered in the PS Vita browser

avatar icon
By
Trooper_D5X
Trooper_D5X was a long-time editor at PlayFront, specializing in gaming news, reviews, and hardware analysis. He authored over 30.000 articles providing in-depth coverage of current topics related to PlayStation...

The PlayStation Vita's own internet browser has a critical security vulnerability in the current firmware 2.05 and presumably also in older versions, which was discovered by majorsecurity.com.

- Advertisement -

A detailed vulnerability description states:

The current version of the web browser installed on the Sony PS Vita system, which is used under firmware 2.05, makes it possible to control and manipulate the displayed content of the address bar as desired.

- Advertisement -

The address bar of the same website is arbitrarily changed in a new window. The user can no longer tell whether they have opened the original or a fake page. Criminals can use this method to carry out phishing attacks, for example. The victim believes they are on a legitimate website. In reality, however, the browser displays a website belonging to fraudsters who want to steal the user's login credentials.

The vulnerability stems from incorrect handling of the URL when the Javascript method "window.open()" is used.

- Advertisement -

Using this method, an attacker can cause the browser to open the requested address in a new window, passing along some values ​​such as a page title, a page URL, or the window size.

In this specific example, the victim thinks they are on the website http://de.playstation.com/psvita/ because this is displayed in the address bar – however, the victim is actually on a website controlled by the attacker.”

- Advertisement -

Majorsecurity recommends refraining from using the PS Vita Browser until the problem is fixed with a patch.

[asa]B009LL5BU8[/asa]

- Advertisement -
Share This Article

SplitScreen Radio Podcast

The current show with Jonas & Bene: Gaming insights, analyses and news.

Community Talk

Subscribe
Notify me
1 Comment
Newest
Oldest Most Voted
Inline feedback
View all comments
- Advertisement -