Web Payments API Vulnerability in Google Chrome
CVE-2017-5110

6.5MEDIUM

Key Information:

Summary

The web payments API in Google Chrome versions before 60.0.3112.78 has a vulnerability due to inappropriate handling of blob: and data: schemes. This flaw allows remote attackers to create a malicious HTML page that can spoof the content displayed in the Omnibox, potentially misleading users and compromising security. Users are advised to update to the latest version of Chrome to mitigate this threat.

Affected Version(s)

Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux and Android Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux and Android

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.