Описание
The content view client in Google Chrome prior to 54.0.2840.85 for Android insufficiently validated intent URLs, which allowed a remote attacker who had compromised the renderer process to start arbitrary activity on the system via a crafted HTML page.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | android only |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was not-affected [android only]] |
| precise | not-affected | android only |
| trusty | not-affected | android only |
| trusty/esm | DNE | trusty was not-affected [android only] |
| upstream | released | 54.0.2840.85 |
| vivid/stable-phone-overlay | DNE | |
| vivid/ubuntu-core | DNE | |
| xenial | not-affected | android only |
| yakkety | not-affected | android only |
Показывать по
6.8 Medium
CVSS2
8.8 High
CVSS3
Связанные уязвимости
The content view client in Google Chrome prior to 54.0.2840.85 for Android insufficiently validated intent URLs, which allowed a remote attacker who had compromised the renderer process to start arbitrary activity on the system via a crafted HTML page.
The content view client in Google Chrome prior to 54.0.2840.85 for And ...
The content view client in Google Chrome prior to 54.0.2840.85 for Android insufficiently validated intent URLs, which allowed a remote attacker who had compromised the renderer process to start arbitrary activity on the system via a crafted HTML page.
Уязвимость браузера Google Chrome, позволяющая нарушителю обойти проверку сертификата
6.8 Medium
CVSS2
8.8 High
CVSS3