First published: Fri Feb 24 2017(Updated: )
Insufficient data validation in filesystem URIs in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
Credit: xisigr Tencent's Xuanwu Lab cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome | <68.0.3440.75 | |
Google Chrome | <68.0.3440.75 | 68.0.3440.75 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
Vulnerability CVE-2018-17460 is a vulnerability in Google Chrome prior to version 68.0.3440.75 that allows a remote attacker to spoof the contents of the Omnibox (URL bar) by using a crafted domain name.
The vulnerability CVE-2018-17460 allows a remote attacker to spoof the contents of the Omnibox (URL bar) in Google Chrome, potentially leading users to believe they are visiting a trusted website when they are not.
The severity of vulnerability CVE-2018-17460 is medium with a CVSS score of 6.5.
To fix vulnerability CVE-2018-17460, users should update their Google Chrome browser to version 68.0.3440.75 or later.
More information about vulnerability CVE-2018-17460 can be found on the Chrome Releases website and the Chromium Bug Tracker.