ios/web/web_state/ui/crw_web_controller.mm in Google Chrome before 52.0.2743.82 on iOS does not ensure that an invalid URL is replaced with the about:blank URL, which allows remote attackers to spoof the URL display via a crafted web site.
References
Configurations
Information
Published : 2016-07-23 12:59
Updated : 2017-08-31 18:29
NVD link : CVE-2016-1707
Mitre link : CVE-2016-1707
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
- chrome