Security Advisory

CVE-2016-5193

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2016-12-18 03:34:00
Last updated 2024-08-06 00:53:48
Assigner Chrome
CVSS score not scored
State PUBLISHED

Description

Google Chrome prior to 54.0 for iOS had insufficient validation of URLs for windows open by DOM, which allowed a remote attacker to bypass restrictions on navigation to certain URL schemes via crafted HTML pages.