CVE-2016-1657

MEDIUM

Google Chrome <50.0.2661.75 - Info Disclosure

Title source: llm

Description

The WebContentsImpl::FocusLocationBarByDefault function in content/browser/web_contents/web_contents_impl.cc in Google Chrome before 50.0.2661.75 mishandles focus for certain about:blank pages, which allows remote attackers to spoof the address bar via a crafted URL.

Scores

CVSS v3 4.3
EPSS 0.0218
EPSS Percentile 84.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Classification

CWE
CWE-254
Status draft

Affected Products (4)

debian/debian_linux
novell/suse_package_hub_for_suse_linux_enterprise
opensuse/leap
google/chrome < 49.0.2623.112

Timeline

Published Apr 18, 2016
Tracked Since Feb 18, 2026