Google Chrome before 39.0.2171.65 on Android does not prevent navigation to a URL in cases where an intent for the URL lacks CATEGORY_BROWSABLE, which allows remote attackers to bypass intended access restrictions via a crafted web site.
References
Configurations
History
No history.
Information
Published : 2014-11-19 11:59
Updated : 2023-11-07 02:21
NVD link : CVE-2014-7905
Mitre link : CVE-2014-7905
CVE.ORG link : CVE-2014-7905
JSON object : View
Products Affected
- chrome
CWE
CWE-284
Improper Access Control