CVE-2017-5096 PUBLISHED

Insufficient policy enforcement during navigation between different schemes in Google Chrome prior to 60.0.3112.78 for Android allowed a remote attacker to perform cross origin content download via a crafted HTML page, related to intents.

EPSS 0.40% · 60.6th percentile

Risk Scores

EPSS Score
0.40%
60.6th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSoxide-qt0, 1.21.5-0ubuntu0.16.04.1, 1.20.4-0ubuntu0.16.04.1
Ubuntu:16.04:LTSchromium-browser55.0.2883.87-0ubuntu0.16.04.1263, 0, 45.0.2454.101-0ubuntu1.1201
Ubuntu:14.04:LTSchromium-browser40.0.2214.94-0ubuntu0.14.04.1.1068, 39.0.2171.65-0ubuntu0.14.04.1.1064, 38.0.2125.111-0ubuntu0.14.04.1.1061

Timeline

References

Open in Interactive Console →