Inappropriate implementation in Download in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to potentially spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)
The user interface (UI) does not properly represent critical information to the user, allowing the information - or its source - to be obscured or spoofed. This is often a component in phishing attacks.
Link | Tags |
---|---|
https://chromereleases.googleblog.com/2023/02/stable-channel-update-for-desktop.html | vendor advisory |
https://crbug.com/1393732 | vendor advisory permissions required |
https://security.gentoo.org/glsa/202309-17 | third party advisory vendor advisory |