Domain Spoofing Vulnerability in Google Chrome by Google
CVE-2017-5076
6.5MEDIUM
Key Information:
- Vendor
- Vendor
- CVE Published:
- 27 October 2017
Summary
The vulnerability allows remote attackers to perform domain spoofing in Google Chrome by exploiting insufficient policy enforcement in the Omnibox. Specifically, crafted domain names utilizing IDN homographs can deceive users, leading them to malicious sites that appear legitimate. This affects various versions of Google Chrome on multiple platforms, thereby putting users at significant risk for phishing and other malicious activity.
Affected Version(s)
Google Chrome prior to 59.0.3071.86 for Mac, Windows and Linux, and 59.0.3071.92 for Android Google Chrome prior to 59.0.3071.86 for Mac, Windows and Linux, and 59.0.3071.92 for Android
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved