URL Handling Vulnerability in Google Chrome on iOS
CVE-2014-3187

Currently unrated

Key Information:

Vendor
Google
Vendor
CVE Published:
8 October 2014

Summary

A significant vulnerability exists in Google Chrome prior to version 37.0.2062.60 and 38.x prior to 38.0.2125.59 on iOS. This flaw allows remote attackers to exploit improperly restricted processing of 'facetime://' and 'facetime-audio://' URLs. By leveraging crafted web pages, an attacker could potentially gain unauthorized access to the audio and video feed of a device, posing severe privacy risks. Users are urged to update their browsers to the latest version to mitigate this exploit.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.