CVE-2016-1707Improper Input Validation in Google Chrome

Severity
6.5MEDIUMNVD
EPSS
0.7%
top 28.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 23
Latest updateMay 17

Description

ios/web/web_state/ui/crw_web_controller.mm in Google Chrome before 52.0.2743.82 on iOS does not ensure that an invalid URL is replaced with the about:blank URL, which allows remote attackers to spoof the URL display via a crafted web site.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages1 packages

NVDgoogle/chrome51.0.2704.106

🔴Vulnerability Details

1
GHSA
GHSA-5774-6xqj-qx8w: ios/web/web_state/ui/crw_web_controller2022-05-17

💥Exploits & PoCs

1
Exploit-DB
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 - Multiple Vulnerabilities2016-11-28

📋Vendor Advisories

1
Red Hat
chromium-browser: url spoofing on ios2016-07-20

💬Community

1
Bugzilla
CVE-2016-1707 chromium-browser: url spoofing on ios2016-07-21