Short Name |
HTTP:STC:CHROME:POPUP-URI-SPOOF |
---|---|
Severity |
Minor |
Recommended |
No |
Recommended Action |
Drop |
Category |
HTTP |
Keywords |
Google Chrome Pop-Up Address Bar URI Spoofing |
Release Date |
2012/12/20 |
Update Number |
2214 |
Supported Platforms |
idp-4.0+, isg-3.1.134269+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+ |
This signature detects attempts to exploit a known vulnerability against Google Chrome. Versions prior to Chrome 0.3.154.9 are vulnerable. A successful attack could allow the attacker to spoof the source URI of a file presented to an unsuspecting user in a popup window.
Google Chrome is affected by a URI-spoofing vulnerability because it fails to adequately handle user-supplied data. An attacker may leverage this issue by inserting arbitrary content to spoof the source URI of a file presented to an unsuspecting user in a popup window. This may lead to a false sense of trust because the victim may be presented with a source URI of a trusted site while interacting with the attacker's malicious site. Versions prior to Chrome 0.3.154.9 are vulnerable.