|
Google Chrome contains a flaw in the 'NavigationController::ClassifyNavigation' function [browser/tab_contents/navigation_controller.cc] that is triggered as interrupted navigation using history.back() is classified as same-page navigation. With a specially crafted web page, a context-dependent attacker can spoof the URL bar.
|