CVE-2014-3187Cross-site Scripting in Google Chrome

Severity
6.8MEDIUMNVD
EPSS
0.5%
top 34.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 8
Latest updateMay 17

Description

Google Chrome before 37.0.2062.60 and 38.x before 38.0.2125.59 on iOS does not properly restrict processing of (1) facetime:// and (2) facetime-audio:// URLs, which allows remote attackers to obtain video and audio data from a device via a crafted web site.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages1 packages

NVDgoogle/chrome37.0.2062.59+53

🔴Vulnerability Details

1
GHSA
GHSA-p4w4-693c-5mf2: Google Chrome before 372022-05-17