Junglewise Threat Intelligence

CVE-2016-5222: Google Chrome address spoofing in Omnibox

CVE-2016-5222 · Severity: medium · CVSS 6.5 · Published 2017-01-19

Technologies: Google Chromium, Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's address bar (Omnibox) could allow a malicious website to display a fake web address to the user. This type of spoofing is often used in phishing attacks to trick users into believing they are on a legitimate site, such as a bank or email provider, when they are actually on a site controlled by an attacker. This could lead to the theft of login credentials or other sensitive personal information.

Technical details

An address spoofing vulnerability exists in the Google Chrome Omnibox component due to improper input validation of invalid URLs. By enticing a user to visit a specially crafted HTML page, a remote attacker can manipulate the displayed URL in the address bar without navigating to that actual location. This flaw stems from incorrect handling of malformed URL strings, which fails to trigger appropriate security UI indicators or reverts to an incorrect state. The vulnerability was patched in Chrome version 55.0.2883.75 for desktop platforms and 55.0.2883.84 for Android.

Affected products

  • Google Chrome < 55.0.2883.75 (Desktop); < 55.0.2883.84 (Android)
  • Google Chromium < 55.0.2883.75

Timeline

  • 2016-12-01: patched: Chrome 55.0.2883.75 released for desktop
  • 2016-12-05: advisory: Gentoo GLSA 201612-11 published
  • 2016-12-07: advisory: Red Hat RHSA-2016:2919 published
  • 2017-01-19: disclosed: NVD publication date

References

Related threats