Executive brief
Google Chrome is a widely used web browser. A vulnerability in how the browser handles PDF navigation allowed attackers to temporarily change the address shown in the URL bar (Omnibox). This could be used in phishing attacks to trick users into believing they are on a legitimate website when they are actually on a malicious one.
Technical details
An address spoofing vulnerability exists in the Google Chrome extensions API due to improper input validation during PDF navigation. By enticing a user to visit a specially crafted HTML page containing PDF data, a remote attacker can temporarily manipulate the URL displayed in the Omnibox. This flaw allows for sophisticated phishing attacks where the user is presented with a fraudulent URL while viewing attacker-controlled content. The issue was addressed by improving navigation handling within the PDF viewer component. The vulnerability affected Chrome for Desktop (Windows, Mac, Linux) and Android.
Affected products
- Google Chrome < 55.0.2883.75 (Desktop); < 55.0.2883.84 (Android)
- Google Chromium < 55.0.2883.75
Timeline
- 2016-12-01: patched: Chrome 55.0.2883.75 released for Desktop
- 2016-12-05: advisory: Gentoo Linux security advisory issued
- 2016-12-07: advisory: Red Hat security advisory issued
- 2017-01-19: disclosed: NVD publication date