CVE-2018-20069
published 2019-01-09CVE-2018-20069: Failure to prevent navigation to top frame to data URLs in Navigation in Google Chrome on iOS prior to 71.0.3578.80 allowed a remote attacker to confuse the…
PriorityP416medium4.3CVSS 3.0
AVNACLPRNUIRSUCNILAN
EPSS
0.43%
35.5th percentile
Failure to prevent navigation to top frame to data URLs in Navigation in Google Chrome on iOS prior to 71.0.3578.80 allowed a remote attacker to confuse the user about the origin of the current page via a crafted HTML page.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | chromium | — | — |
| chrome | < 71.0.3578.80 | 71.0.3578.80 | |
| chrome | >= unspecified < 71.0.3578.80 | 71.0.3578.80 |
CVSS provenance
nvdv3.04.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_debian4.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2018-20069: chromium - Failure to prevent navigation to top frame to data URLs in Navigation in Google ...
vendor_debian·2018·CVSS 4.3
CVE-2018-20069 [MEDIUM] CVE-2018-20069: chromium - Failure to prevent navigation to top frame to data URLs in Navigation in Google ...
Failure to prevent navigation to top frame to data URLs in Navigation in Google Chrome on iOS prior to 71.0.3578.80 allowed a remote attacker to confuse the user about the origin of the current page via a crafted HTML page.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-c6vv-wc55-crp5: Failure to prevent navigation to top frame to data URLs in Navigation in Google Chrome on iOS prior to 71
ghsa_unreviewed·2022-05-13
CVE-2018-20069 [MEDIUM] GHSA-c6vv-wc55-crp5: Failure to prevent navigation to top frame to data URLs in Navigation in Google Chrome on iOS prior to 71
Failure to prevent navigation to top frame to data URLs in Navigation in Google Chrome on iOS prior to 71.0.3578.80 allowed a remote attacker to confuse the user about the origin of the current page via a crafted HTML page.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-01-09
Published