Address bar spoofing vulnerability in Google Chrome via a vectors involving the document.write method (rpm).ID: oval:org.secpod.oval:def:16153 | Date: (C)2013-12-10 (M)2023-11-16 |
Class: VULNERABILITY | Family: unix |
The host is installed with Google Chrome before 31.0.1650.63 and is prone to address bar spoofing vulnerability. The flaw is present in the application, which fails to handle the FrameLoader::notifyIfInitialDocumentAccessed function. Successful exploitation allows the remote attacker to spoof the address bar via vectors involving the document.write method.