CVE-2016-1707 is a URL spoofing vulnerability affecting Google Chrome on iOS prior to version 52.0.2743.82. This flaw allows a remote attacker, via a crafted website, to display an invalid URL instead of the expected about:blank, potentially deceiving users. Rated as medium severity (CVSS 6.5), it has a low attack complexity and requires user interaction, but could lead to high integrity impact through spoofing. There is no evidence of active exploitation, and no public exploit code or Metasploit modules are available. While it received some media coverage upon disclosure, community discussion is minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 51.0.2704.106CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.