Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:28117
HistoryDec 06, 2020 - 3:06 a.m.

Authorization Bypass

2020-12-0603:06:12
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9
chromium
authorization bypass
omnibox
google chrome
spoofing
crafted domain name

EPSS

0.007

Percentile

80.5%

chromium is vulnerable to authorization bypass. The library does not properly handle the confusable characters in Omnibox in Google Chrome, allowing an attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.