Man-in-the-middle attack vulnerability in the Spellcheck API implementation in Google Chrome via a crafted file (dpkg)ID: oval:org.secpod.oval:def:24929 | Date: (C)2015-06-12 (M)2022-07-06 |
Class: VULNERABILITY | Family: unix |
The host is installed with Google Chrome before 43.0.2357.65 and is prone to a man-in-the-middle vulnerability. A flaw is present in the application, which does not use an HTTPS session for downloading a Hunspell dictionary. Successful exploitation could allow attackers to deliver incorrect spelling suggestions or possibly have unspecified other impact.