CVE-2018-17464: Medium severity google chrome vulnerability
An url spoof flaw was found in the Omnibox component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=887273
External References:
https://chromereleases.googleblog.com/2018/10/stable-channel-update-for-desktop.html
Other sources
Incorrect handling of history on iOS in Navigation in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-17464?
The severity of CVE-2018-17464 is high.
How does CVE-2018-17464 affect Google Chrome?
CVE-2018-17464 affects Google Chrome versions prior to 70.0.3538.67 on iOS.
Can a remote attacker exploit CVE-2018-17464?
Yes, a remote attacker can exploit CVE-2018-17464 to spoof the contents of the Omnibox (URL bar).
Is there a fix available for CVE-2018-17464?
Yes, updating Google Chrome to version 70.0.3538.67 or later will fix CVE-2018-17464.
Where can I find more information about CVE-2018-17464?
You can find more information about CVE-2018-17464 on SecurityFocus, Red Hat, and the Google Chrome Releases blog.