CVE-2016-1657 PUBLISHED

The WebContentsImpl::FocusLocationBarByDefault function in content/browser/web_contents/web_contents_impl.cc in Google Chrome before 50.0.2661.75 mishandles focus for certain about:blank pages, which allows remote attackers to spoof the address bar via a crafted URL.

EPSS 2.18% · 84.2th percentile

Risk Scores

EPSS Score
2.18%
84.2th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSchromium-browser0, 45.0.2454.101-0ubuntu1.1201, 47.0.2526.73-0ubuntu1.1218
Ubuntu:14.04:LTSchromium-browser37.0.2062.120-0ubuntu0.14.04.1~pkg1049, 38.0.2125.111-0ubuntu0.14.04.1.1061, 39.0.2171.65-0ubuntu0.14.04.1.1064

Timeline

References

Open in Interactive Console →