Remote Code Execution Vulnerability in ChromeVox on Google Chrome OS
CVE-2017-15397

7.4HIGH

Key Information:

Vendor
Google
Vendor
CVE Published:
7 February 2018

Summary

An issue within the ChromeVox screen reader component of Google Chrome OS prior to version 62.0.3202.74 allows a remote attacker positioned in a privileged network to intercept or manipulate cleartext HTTP requests. This vulnerability can lead to potential data exposure and compromise the integrity of communications over the network, highlighting the importance of secure transmission protocols.

Affected Version(s)

Google Chrome OS prior to 62.0.3202.74 Google Chrome OS prior to 62.0.3202.74

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.