Security Advisory

CVE-2017-15427

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2018-08-28 19:00:00
Last updated 2024-08-05 19:57:26
Assigner Chrome
CVSS score not scored
State PUBLISHED

Description

Insufficient policy enforcement in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a socially engineered user to XSS themselves by dragging and dropping a javascript: URL into the URL bar.