CVE-2018-17472: Input Validation
Published Nov 14, 2018
·Updated
Incorrect handling of googlechrome:// URL scheme on iOS in Intents in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to escape the <iframe> sandbox via a crafted HTML page.
Affected Software
6 affected components
Google Chrome<70.0.3538.67
Apple iPhone OS
redhat Enterprise Linux Desktop=6.0
redhat Enterprise Linux Server=6.0
redhat Enterprise Linux Workstation=6.0
Debian Debian Linux=9.0
Event History
Nov 14, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-17472?
CVE-2018-17472 has a moderate severity rating as it allows for sandbox escape via a crafted HTML page.
2
How do I fix CVE-2018-17472?
To fix CVE-2018-17472, upgrade Google Chrome to version 70.0.3538.67 or later.
3
What does CVE-2018-17472 affect?
CVE-2018-17472 affects Google Chrome versions prior to 70.0.3538.67 on iOS.
4
Can CVE-2018-17472 be exploited remotely?
Yes, CVE-2018-17472 can be exploited remotely by using a crafted HTML page.
5
What is the main issue described in CVE-2018-17472?
The main issue described in CVE-2018-17472 is the incorrect handling of the googlechrome:// URL scheme in Intents on iOS.