ios/web/web_state/ui/crw_web_controller.mm in Google Chrome before 52.0.2743.82 on iOS does not ensure that an invalid URL is replaced with the about:blank URL, which allows remote attackers to spoof the URL display via a crafted web site.
References
Configurations
History
No history.
Information
Published : 2016-07-23 19:59
Updated : 2024-02-04 18:53
NVD link : CVE-2016-1707
Mitre link : CVE-2016-1707
CVE.ORG link : CVE-2016-1707
JSON object : View
Products Affected
- chrome
CWE
CWE-20
Improper Input Validation