CVE-2018-20069 describes a vulnerability in Google Chrome on iOS, prior to version 71.0.3578.80, where it failed to prevent navigation to top frame data URLs. This allowed a remote attacker to craft an HTML page that could confuse users about the true origin of the current page. Rated as Medium severity (CVSS 4.3), this vulnerability requires user interaction (UI:R) and could lead to information integrity issues (I:L) without impacting confidentiality or availability. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Despite low community discussion and media coverage, its FAUCET Risk Score of 9/100 suggests a non-trivial risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 71.0.3578.80CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.