URL Handling Vulnerability in Google Chrome on iOS
CVE-2014-3187
Currently unrated
Summary
A significant vulnerability exists in Google Chrome prior to version 37.0.2062.60 and 38.x prior to 38.0.2125.59 on iOS. This flaw allows remote attackers to exploit improperly restricted processing of 'facetime://' and 'facetime-audio://' URLs. By leveraging crafted web pages, an attacker could potentially gain unauthorized access to the audio and video feed of a device, posing severe privacy risks. Users are urged to update their browsers to the latest version to mitigate this exploit.
References
Timeline
Vulnerability published
Vulnerability Reserved