AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2021-23253

MEDIUM · CVSS 5.3 EPSS 0.75%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2021-01-11 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 5.3. It affects Android.

CVE
CVE-2021-23253
Severity
MEDIUM
CVSS
5.3
EPSS
0.75%
Android

Original NVD Description

Opera Mini for Android below 53.1 displays URL left-aligned in the address field. This allows a malicious attacker to craft a URL with a long domain name, e.g. www.safe.opera.com.attacker.com. With the URL being left-aligned, the user will only see the front part (e.g. www.safe.opera.com…) The exact amount depends on the phone screen size but the attacker can craft a number of different domains and target different phones. Starting with version 53.1 Opera Mini displays long URLs with the top-level domain label aligned to the right of the address field which mitigates the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)