Security Advisory

CVE-2015-1278

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2015-07-23 00:00:00
Last updated 2024-08-06 04:40:18
Assigner Chrome
CVSS score not scored
State PUBLISHED

Description

content/browser/web_contents/web_contents_impl.cc in Google Chrome before 44.0.2403.89 does not ensure that a PDF document's modal dialog is closed upon navigation to an interstitial page, which allows remote attackers to spoof URLs via a crafted document, as demonstrated by the alert_dialog.pdf document.