ZeroHour

CVE-2017-5118

CVSS 3.1
4.3 medium
EPSS
1%p65
Published
()
Modified
Description

Blink in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.3163.81 for Android, failed to correctly propagate CSP restrictions to javascript scheme pages, which allowed a remote attacker to bypass content security policy via a crafted HTML page.

Vendors
googledebianredhat
Products
chrome, debian linux, enterprise linux desktop, enterprise linux server, enterprise linux workstation
Weakness
CWE-732
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.