CVE-2017-5072Improper Input Validation in Google Chrome

Severity
6.5MEDIUMNVD
EPSS
0.5%
top 33.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 27
Latest updateMay 14

Description

Inappropriate implementation in Omnibox in Google Chrome prior to 59.0.3071.92 for Android allowed a remote attacker to perform domain spoofing with RTL characters via a crafted URL page.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages1 packages

NVDgoogle/chrome< 59.0.3071.92

🔴Vulnerability Details

2
GHSA
GHSA-38hg-868p-r35x: Inappropriate implementation in Omnibox in Google Chrome prior to 592022-05-14
OSV
CVE-2017-5072: Inappropriate implementation in Omnibox in Google Chrome prior to 592017-10-27

📋Vendor Advisories

1
Red Hat
chromium-browser: address spoofing in omnibox2017-06-05

💬Community

2
Bugzilla
chromium: various flaws [fedora-all]2017-06-06
Bugzilla
CVE-2017-5072 chromium-browser: address spoofing in omnibox2017-06-06