Security changelogs

February 2017
Fixed in version 16.10
27 February 2017, 09:00

CVE-2016-8507: mohaab007

Yandex Browser for iOS before does not properly restrict processing of facetime:// URLs, which allows remote attackers to initiate facetime-call without user's approval and obtain video and audio data from a device via a crafted web site. 

No comments
Fixed in version 17.1
27 February 2017, 09:10

CVE-2016-8508: Oleynik Yaroslav

Yandex Browser for desktop before does not show Protect (similar to Safebrowsing in Chromium) warnigns in web-sites with special content-type, which could be used by remote attacker for prevention Protect warning on own malicious web-site.

1 comment