CVE-2017-15427 PUBLISHED

Insufficient policy enforcement in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a socially engineered user to XSS themselves by dragging and dropping a javascript: URL into the URL bar.

EPSS 0.37% · 58.8th percentile

Risk Scores

EPSS Score
0.37%
58.8th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSoxide-qt1.11.3-0ubuntu3, 1.12.6-0ubuntu1, 1.12.5-0ubuntu1
Ubuntu:18.04:LTSchromium-browser62.0.3202.94-0ubuntu1.1388, 62.0.3202.89-0ubuntu1.1386, 62.0.3202.62-0ubuntu0.17.10.1380
Ubuntu:14.04:LTSchromium-browser*, 47.0.2526.73-0ubuntu0.14.04.1.1106, *
Ubuntu:16.04:LTSchromium-browser62.0.3202.75-0ubuntu0.16.04.1313, 50.0.2661.102-0ubuntu0.16.04.1.1237, 48.0.2564.82-0ubuntu1.1222

Timeline

References

Open in Interactive Console →