Field Assessment
AI analysis pending.
CVE
CVE-2017-15427
Severity
MEDIUM
CVSS
6.1
EPSS
0.86%
Chrome Java
Original Filing — NVD Description
Insufficient policy enforcement in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a socially engineered user to XSS themselves by dragging and dropping a javascript: URL into the URL bar.