Inadequate Modal Dialog Handling in Google Chrome Affects Multiple Platforms
CVE-2017-5093
6.5MEDIUM
Key Information:
- Vendor
- Vendor
- CVE Published:
- 27 October 2017
Summary
A vulnerability in Google Chrome's modal dialog handling mechanism allows an attacker to manipulate the display of a full screen warning. This flaw, present in the Blink rendering engine, can be exploited via specially crafted HTML pages. By bypassing the expected warning alerts, a malicious actor can create a misleading interface, posing risks to user security and potentially leading to further attacks.
Affected Version(s)
Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux and Android Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux and Android
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved