First published: Wed Apr 09 2014(Updated: )
The UnescapeURLWithOffsetsImpl function in net/base/escape.cc in Google Chrome before 34.0.1847.116 does not properly handle bidirectional Internationalized Resource Identifiers (IRIs), which makes it easier for remote attackers to spoof URLs via crafted use of right-to-left (RTL) Unicode text.
Credit: cve-coordination@google.com chrome-cve-admin@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome (Trace Event) | <=34.0.1847.115 | |
Google Chrome | <=34.0.1847.115 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-1723 is classified as a medium severity vulnerability due to its potential to facilitate URL spoofing.
To fix CVE-2014-1723, update your Google Chrome to version 34.0.1847.116 or later.
The impact of CVE-2014-1723 allows attackers to spoof URLs, which could deceive users into clicking malicious links.
Google Chrome versions prior to 34.0.1847.116 are affected by CVE-2014-1723.
Yes, CVE-2014-1723 can be exploited remotely by attackers through specially crafted Unicode text.