ZeroHour

CVE-2016-1657

CVSS 3.0
4.3 medium
EPSS
1%p71
Published
()
Modified
Description

The WebContentsImpl::FocusLocationBarByDefault function in content/browser/web_contents/web_contents_impl.cc in Google Chrome before 50.0.2661.75 mishandles focus for certain about:blank pages, which allows remote attackers to spoof the address bar via a crafted URL.

Vendors
debiannovellopensusegoogle
Products
debian linux, suse package hub for suse linux enterprise, leap, chrome
Weakness
CWE-254
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.