CVE-2017-5072: Input Validation
An address spoofing flaw was found in the Omnibox component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=709417
External References:
https://chromereleases.googleblog.com/2017/06/stable-channel-update-for-desktop.html
Other sources
Inappropriate implementation in Omnibox in Google Chrome prior to 59.0.3071.92 for Android allowed a remote attacker to perform domain spoofing with RTL characters via a crafted URL page.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5072?
CVE-2017-5072 has a medium severity rating, indicating a potential risk to users due to domain spoofing.
How do I fix CVE-2017-5072?
To fix CVE-2017-5072, update Google Chrome to version 59.0.3071.92 or later.
Who is affected by CVE-2017-5072?
CVE-2017-5072 affects users of Google Chrome versions prior to 59.0.3071.92 on Android devices.
What type of vulnerability is CVE-2017-5072?
CVE-2017-5072 is a domain spoofing vulnerability in the Omnibox component of Google Chrome.
Can CVE-2017-5072 be exploited remotely?
Yes, CVE-2017-5072 can be exploited remotely by an attacker using crafted URLs.