CVE-2017-5072 describes a domain spoofing vulnerability in Google Chrome for Android, specifically in versions prior to 59.0.3071.92. This flaw allowed remote attackers to display a deceptive URL in the Omnibox using crafted RTL characters. Rated Medium severity (CVSS 6.5), it requires user interaction (UI:R) but could lead to high integrity impact (I:H) by tricking users into believing they are on a legitimate site. While there is no evidence of active exploitation (KEV: No) and no public exploit code (Metasploit, Nuclei, ExploitDB: None), the vulnerability garnered significant community discussion and media coverage, indicating awareness of its potential.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 59.0.3071.92CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.