First published: Wed Jan 09 2019(Updated: )
Failure to prevent navigation to top frame to data URLs in Navigation in Google Chrome on iOS prior to 71.0.3578.80 allowed a remote attacker to confuse the user about the origin of the current page via a crafted HTML page.
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome | <71.0.3578.80 | |
Apple iPhone OS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-20069 is classified as a medium severity vulnerability.
To fix CVE-2018-20069, update Google Chrome to version 71.0.3578.80 or later.
CVE-2018-20069 affects Google Chrome on iOS prior to version 71.0.3578.80.
CVE-2018-20069 involves confusion about the origin of the current page due to navigation vulnerabilities.
Yes, CVE-2018-20069 can be exploited remotely by an attacker through a crafted HTML page.