CVE-2018-20070: Input Validation
Published Jan 9, 2019
·Updated
Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
Affected Software
1 affected component
Google Chrome<71.0.3578.80
Event History
Jan 9, 2019
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-20070?
CVE-2018-20070 has a high severity rating due to its potential for phishing attacks through URL spoofing.
2
How do I fix CVE-2018-20070?
To mitigate CVE-2018-20070, users should update Google Chrome to version 71.0.3578.80 or later.
3
What versions of Google Chrome are affected by CVE-2018-20070?
CVE-2018-20070 affects Google Chrome versions prior to 71.0.3578.80.
4
What type of attack does CVE-2018-20070 enable?
CVE-2018-20070 enables attackers to perform URL spoofing, potentially leading to phishing attacks.
5
How does CVE-2018-20070 impact users?
CVE-2018-20070 impacts users by allowing malicious actors to deceive them into believing they are visiting legitimate websites.