First published: Tue Jun 06 2017(Updated: )
Inappropriate implementation in Omnibox in Google Chrome prior to 59.0.3071.92 for Android allowed a remote attacker to perform domain spoofing with RTL characters via a crafted URL page.
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/Chrome | <59.0.3071.86 | 59.0.3071.86 |
Google Chrome (Trace Event) | <59.0.3071.92 | |
Android |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-5072 has a medium severity rating, indicating a potential risk to users due to domain spoofing.
To fix CVE-2017-5072, update Google Chrome to version 59.0.3071.92 or later.
CVE-2017-5072 affects users of Google Chrome versions prior to 59.0.3071.92 on Android devices.
CVE-2017-5072 is a domain spoofing vulnerability in the Omnibox component of Google Chrome.
Yes, CVE-2017-5072 can be exploited remotely by an attacker using crafted URLs.