Web Payments API Vulnerability in Google Chrome
CVE-2017-5110
6.5MEDIUM
Key Information:
- Vendor
- Vendor
- CVE Published:
- 27 October 2017
Summary
The web payments API in Google Chrome versions before 60.0.3112.78 has a vulnerability due to inappropriate handling of blob: and data: schemes. This flaw allows remote attackers to create a malicious HTML page that can spoof the content displayed in the Omnibox, potentially misleading users and compromising security. Users are advised to update to the latest version of Chrome to mitigate this threat.
Affected Version(s)
Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux and Android Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux and Android
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved