CVE-2014-3159

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
20/07/2014
Last modified:
12/04/2025

Description

The WebContentsDelegateAndroid::OpenURLFromTab function in components/web_contents_delegate_android/web_contents_delegate_android.cc in Google Chrome before 36.0.1985.122 on Android does not properly restrict URL loading, which allows remote attackers to spoof the URL in the Omnibox via unspecified vectors.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* 36.0.1985.106 (including)
cpe:2.3:a:google:chrome:36.0.1985.1:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:36.0.1985.2:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:36.0.1985.3:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:36.0.1985.4:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:36.0.1985.5:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:36.0.1985.6:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:36.0.1985.8:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:36.0.1985.12:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:36.0.1985.13:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:36.0.1985.14:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:36.0.1985.15:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:36.0.1985.16:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:36.0.1985.17:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:36.0.1985.18:*:*:*:*:*:*:*