CVE-2017-15419
—CVSS 3.0
6.5 medium
EPSS
1%p68
Published
()
Modified
Description
Insufficient policy enforcement in Resource Timing API in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to infer browsing history by triggering a leaked cross-origin URL via a crafted HTML page.
In the news0 stories
No ingested article mentions this CVE yet.