The Yahoo! Browser application before 1.4.3 for Android allows remote attackers to spoof the address bar via a crafted web site.
https://play.google.com/store/apps/details?id=jp.co.yahoo.android.ybrowser
https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-2253