Remote Code Execution Vulnerability in Google Chrome
CVE-2017-5075
4.3MEDIUM
Key Information:
- Vendor
- Vendor
- CVE Published:
- 27 October 2017
Summary
A vulnerability exists in Google Chrome's implementation of Content Security Policy (CSP) reporting that can allow remote attackers to access URL fragments. This security flaw affects users on Linux, Windows, Mac, and Android running versions prior to specified updates. By crafting a malicious HTML page, attackers can exploit this issue to extract sensitive data. It is crucial for users to update their browsers to protect against this vulnerability.
Affected Version(s)
Google Chrome prior to 59.0.3071.86 for Linux, Windows and Mac, and 59.0.3071.92 for Android Google Chrome prior to 59.0.3071.86 for Linux, Windows and Mac, and 59.0.3071.92 for Android
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved