The WebContentsImpl::FocusLocationBarByDefault function in content/browser/web_contents/web_contents_impl.cc in Google Chrome before 50.0.2661.75 mishandles focus for certain about:blank pages, which allows remote attackers to spoof the address bar via a crafted URL.
2016-04-18T10:59:06.093
2025-04-12T10:46:40.837
Deferred
CVSSv3.0: 4.3 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | debian | debian_linux | 8.0 | Yes |
Application | novell | suse_package_hub_for_suse_linux_enterprise | 12 | Yes |
Operating System | opensuse | leap | 42.1 | Yes |
Application | chrome | ≤ 49.0.2623.112 | Yes |