User Interface Exposure in Google Chrome by Remote Attackers
CVE-2017-5083

4.3MEDIUM

Summary

A vulnerability in Google Chrome's Blink engine allowed remote attackers to manipulate the user interface through a crafted HTML page. This issue affects users across multiple operating systems including Mac, Windows, Linux, and Android. Attackers could potentially trick users into interacting with malicious content in an uncontrolled tab, compromising the intended browser experience. Immediate updates to the browser are recommended to mitigate such risks.

Affected Version(s)

Google Chrome prior to 59.0.3071.86 for Mac, Windows and Linux, and 59.0.3071.92 for Android Google Chrome prior to 59.0.3071.86 for Mac, Windows and Linux, and 59.0.3071.92 for Android

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.