#VU54380 Spoofing attack in NVIDIA App (formerly GeForce Experience) - CVE-2021-1073
Published: June 25, 2021
NVIDIA App (formerly GeForce Experience)
nVidia
Description
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to incorrect processing of special formatted links in NVIDIA GeForce Experience software. A remote attacker can create a specially crafted link that opens the GeForce Experience login page in a new browser tab instead of the GeForce Experience application and enters their login information, the malicious site can get access to the token of the user login session.