CVE-2016-6586

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
08/01/2020
Last modified:
15/01/2020

Description

A security bypass vulnerability exists in Symantec Norton Mobile Security for Android before 3.16, which could let a malicious user conduct a man-in-the-middle via specially crafted JavaScript to add arbitrary URLs to the URL whitelist.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:symantec:norton_mobile_security:*:*:*:*:*:android:*:* 3.16 (excluding)