CVE Published: 28/08/2018 |
CVE Updated: 05/08/2024 |
CVE Year: 2017 Source: Chrome |
Vendor: n/a |
Product: Google Chrome prior to 63.0.3239.84 unknown Status : PUBLISHED
CVE-2017-15427 Description
Insufficient policy enforcement in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a socially engineered user to XSS themselves by dragging and dropping a javascript: URL into the URL bar.