Insufficient Watchdog Timer in Google Chrome Can Lead to URL Spoofing
CVE-2017-5067
6.5MEDIUM
Key Information:
- Vendor
Google
- Vendor
- CVE Published:
- 27 October 2017
What is CVE-2017-5067?
A vulnerability in Google Chrome prior to version 58.0.3029.81 for Linux, Windows, and Mac allows attackers to manipulate the Omnibox content. This issue arises from an inadequate watchdog timer during navigation, enabling remote attackers to craft specific HTML pages to spoof URLs displayed in the address bar. Users may be misled into believing they are visiting a legitimate site, thereby posing significant security risks.
Affected Version(s)
Google Chrome prior to 58.0.3029.81 for Linux, Windows and Mac Google Chrome prior to 58.0.3029.81 for Linux, Windows and Mac