The UnescapeURLWithAdjustmentsImpl implementation in net/base/escape.cc in Google Chrome before 45.0.2454.85 does not prevent display of Unicode LOCK characters in the omnibox, which makes it easier for remote attackers to spoof the SSL lock icon by placing one of these characters at the end of a URL, as demonstrated by the omnibox in localizations for right-to-left languages.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: Chrome
Published:
Updated: 2024-08-06T04:40:17.973Z
Reserved: 2015-01-21T00:00:00
Link: CVE-2015-1296

No data.

Status : Deferred
Published: 2015-09-03T22:59:06.813
Modified: 2025-04-12T10:46:40.837
Link: CVE-2015-1296
