CVE-2014-3187
Google Chrome < 37.0.2062.60 - Unauthenticated Video/Audio Capture via URL Processing
Title source: llmDescription
Google Chrome before 37.0.2062.60 and 38.x before 38.0.2125.59 on iOS does not properly restrict processing of (1) facetime:// and (2) facetime-audio:// URLs, which allows remote attackers to obtain video and audio data from a device via a crafted web site.
References (4)
Core 4
Core References
Issue Tracking x_refsource_confirm
https://code.google.com/p/chromium/issues/detail?id=413831
Various Sources x_refsource_misc
https://medium.com/section-9-lab/abusing-ios-url-handlers-on-messages-96979e8b12f5
Various Sources x_refsource_misc
http://twitter.com/S9Labs/statuses/519576582742999043
Release Notes, Vendor Advisory x_refsource_confirm
http://googlechromereleases.blogspot.com/2014/10/chrome-for-ios-update.html
Scores
EPSS
0.0081
EPSS Percentile
53.2%
Details
CWE
CWE-79
Status
published
Products (50)
apple/iphone_os
google/chrome
37.0.2062.0
google/chrome
37.0.2062.1
google/chrome
37.0.2062.2
google/chrome
37.0.2062.3
google/chrome
37.0.2062.4
google/chrome
37.0.2062.5
google/chrome
37.0.2062.6
google/chrome
37.0.2062.10
google/chrome
37.0.2062.11
... and 40 more
Published
Oct 08, 2014
Tracked Since
Feb 18, 2026