Domain Spoofing Vulnerability in Google Chrome Omnibox
CVE-2017-15425
6.5MEDIUM
Key Information:
- Vendor
Google
- Vendor
- CVE Published:
- 28 August 2018
What is CVE-2017-15425?
The vulnerability stems from insufficient policy enforcement in the Omnibox component of Google Chrome, which could allow a remote attacker to exploit IDN homographs. This exploit enables attackers to craft misleading domain names that appear similar to legitimate URLs, misleading users and potentially leading to phishing attacks. Users could unknowingly navigate to malicious sites that mimic trusted domains, compromising sensitive information and jeopardizing online security.
Affected Version(s)
Google Chrome prior to 63.0.3239.84 unknown Google Chrome prior to 63.0.3239.84 unknown