Security changelogs

February 2017
Fixed in version 16.10
27 February, 09:00

CVE-2016-8507: mohaab007

Yandex Browser for iOS before 16.10.0.2357 does not properly restrict processing of facetime:// URLs, which allows remote attackers to initiate facetime-call without user's approval and obtain video and audio data from a device via a crafted web site. 

No comments
CVE-2016-8507
Fixed in version 17.1
27 February, 09:10

CVE-2016-8508: Oleynik Yaroslav

Yandex Browser for desktop before 17.1.1.227 does not show Protect (similar to Safebrowsing in Chromium) warnigns in web-sites with special content-type, which could be used by remote attacker for prevention Protect warning on own malicious web-site.

No comments
CVE-2016-8508