CVE-2017-15420Improper Input Validation in Google Chrome

Severity
6.5MEDIUMNVD
EPSS
0.9%
top 24.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 28
Latest updateMay 14

Description

Incorrect handling of back navigations in error pages in Navigation in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages5 packages

CVEListV5google/chromeunspecified63.0.3239.84
NVDgoogle/chrome< 63.0.3239.84

Also affects: Debian Linux 8.0, 9.0

🔴Vulnerability Details

2
GHSA
GHSA-6463-qrm9-ch2m: Incorrect handling of back navigations in error pages in Navigation in Google Chrome prior to 632022-05-14
OSV
CVE-2017-15420: Incorrect handling of back navigations in error pages in Navigation in Google Chrome prior to 632018-08-28

📋Vendor Advisories

1
Red Hat
chromium-browser: url spoofing in omnibox2017-12-06

💬Community

3
Bugzilla
CVE-2017-15420 chromium-browser: url spoofing in omnibox2017-12-07
Bugzilla
CVE-2017-15407 CVE-2017-15408 CVE-2017-15409 CVE-2017-15410 CVE-2017-15411 CVE-2017-15412 CVE-2017-15413 CVE-2017-15415 CVE-2017-15416 CVE-2017-15417 CVE-2017-15418 CVE-2017-15419 CVE-2017-15420 CVE-22017-12-07
Bugzilla
CVE-2017-15407 CVE-2017-15408 CVE-2017-15409 CVE-2017-15410 CVE-2017-15411 CVE-2017-15412 CVE-2017-15413 CVE-2017-15415 CVE-2017-15416 CVE-2017-15417 CVE-2017-15418 CVE-2017-15419 CVE-2017-15420 CVE-22017-12-07
CVE-2017-15420 — Improper Input Validation in Google | cvebase