Learn about CVE-2017-15420, a Google Chrome vulnerability allowing remote attackers to manipulate Omnibox content. Find mitigation steps and long-term security practices here.
Google Chrome prior to version 63.0.3239.84 had a vulnerability in the Navigation feature that allowed a remote attacker to manipulate the content displayed in the Omnibox using a specially crafted HTML page.
Understanding CVE-2017-15420
This CVE entry describes a flaw in Google Chrome that could be exploited by attackers to spoof the contents of the Omnibox.
What is CVE-2017-15420?
The vulnerability in Google Chrome's Navigation feature led to incorrect handling of back navigations on error pages, enabling attackers to manipulate the content displayed in the Omnibox using a specially crafted HTML page.
The Impact of CVE-2017-15420
The vulnerability could be exploited by a remote attacker to spoof the contents of the Omnibox (URL bar) in Google Chrome.
Technical Details of CVE-2017-15420
Google Chrome vulnerability details and affected systems.
Vulnerability Description
Prior to version 63.0.3239.84, Google Chrome incorrectly handled back navigations on error pages, allowing remote attackers to manipulate the content displayed in the Omnibox using a specially crafted HTML page.
Affected Systems and Versions
Exploitation Mechanism
The flaw in the Navigation feature of Google Chrome could be exploited by a remote attacker to manipulate the content displayed in the Omnibox using a specially crafted HTML page.
Mitigation and Prevention
Steps to mitigate and prevent the CVE-2017-15420 vulnerability.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates