Your submission was sent successfully! Close

You have successfully unsubscribed! Close

CVE-2016-5187

Published: 17 October 2016

Google Chrome prior to 54.0.2840.85 for Android incorrectly handled rapid transition into and out of full screen mode, which allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via crafted HTML pages.

Notes

AuthorNote
chrisccoulson
This looks like it's in the TopControlsManager, used only
in Chrome/Android. Oxide also makes use of this functionality

Priority

Medium

CVSS 3 base score: 6.5

Status

Package Release Status
chromium-browser
Launchpad, Ubuntu, Debian
precise Ignored

trusty Does not exist
(trusty was not-affected)
upstream Not vulnerable

xenial Not vulnerable

yakkety Not vulnerable

oxide-qt
Launchpad, Ubuntu, Debian
precise Does not exist

trusty Does not exist
(trusty was released [1.18.3-0ubuntu0.14.04.1])
upstream
Released (1.18.3)
xenial
Released (1.18.3-0ubuntu0.16.04.1)
yakkety
Released (1.18.3-0ubuntu0.16.10.1)