CVE-2017-5076: Input Validation
An address spoofing flaw was found in the Omnibox component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=719199
External References:
https://chromereleases.googleblog.com/2017/06/stable-channel-update-for-desktop.html
Other sources
Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 59.0.3071.86 for Mac, Windows, and Linux, and 59.0.3071.92 for Android, allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5076?
CVE-2017-5076 has a high severity rating due to its potential for domain spoofing.
How do I fix CVE-2017-5076?
To fix CVE-2017-5076, update Google Chrome to version 59.0.3071.86 or later.
Who is affected by CVE-2017-5076?
CVE-2017-5076 affects users of Google Chrome versions prior to 59.0.3071.86 on Mac, Windows, and Linux.
What type of attack does CVE-2017-5076 facilitate?
CVE-2017-5076 allows remote attackers to perform domain spoofing through IDN homographs.
Is CVE-2017-5076 relevant for Android users?
CVE-2017-5076 is relevant for Android users running Chrome versions prior to 59.0.3071.92.