Folks at CM used sample code from Oracle and left CM open to a known MIM attack. It will be an easy fix but be real careful using the browser on public WiFi until it is fixed
Android s Cyanogenmod open to MitM attacks The Register
Android s Cyanogenmod open to MitM attacks The Register