6.8
CVSSv2

CVE-2014-3187

Published: 08/10/2014 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Google Chrome prior to 37.0.2062.60 and 38.x prior to 38.0.2125.59 on iOS does not properly restrict processing of (1) facetime:// and (2) facetime-audio:// URLs, which allows remote malicious users to obtain video and audio data from a device via a crafted web site.

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome

google chrome 37.0.2062.0

google chrome 37.0.2062.1

google chrome 37.0.2062.2

google chrome 37.0.2062.3

google chrome 37.0.2062.4

google chrome 37.0.2062.5

google chrome 37.0.2062.6

google chrome 37.0.2062.10

google chrome 37.0.2062.11

google chrome 37.0.2062.12

google chrome 37.0.2062.13

google chrome 37.0.2062.14

google chrome 37.0.2062.15

google chrome 37.0.2062.16

google chrome 37.0.2062.17

google chrome 37.0.2062.18

google chrome 37.0.2062.19

google chrome 37.0.2062.20

google chrome 37.0.2062.21

google chrome 37.0.2062.22

google chrome 37.0.2062.23

google chrome 37.0.2062.24

google chrome 37.0.2062.25

google chrome 37.0.2062.26

google chrome 37.0.2062.27

google chrome 37.0.2062.28

google chrome 37.0.2062.29

google chrome 37.0.2062.30

google chrome 37.0.2062.31

google chrome 37.0.2062.32

google chrome 37.0.2062.33

google chrome 37.0.2062.34

google chrome 37.0.2062.35

google chrome 37.0.2062.36

google chrome 37.0.2062.37

google chrome 37.0.2062.39

google chrome 37.0.2062.43

google chrome 37.0.2062.44

google chrome 37.0.2062.45

google chrome 37.0.2062.46

google chrome 37.0.2062.47

google chrome 37.0.2062.48

google chrome 37.0.2062.49

google chrome 37.0.2062.50

google chrome 37.0.2062.51

google chrome 37.0.2062.52

google chrome 37.0.2062.53

google chrome 37.0.2062.54

google chrome 37.0.2062.55

google chrome 37.0.2062.56

google chrome 37.0.2062.57

google chrome 37.0.2062.58

google chrome 38.0.2125.7

apple iphone_os -

Github Repositories

Section9Labs Vulnerability Advisories.

Advisories Section9Labs Vulnerability Advisories CVE-2014-3187 - Google Chrome FaceTime & FaceTime Audio arbitrary calls CVE-2014-7305 - Mercury Web Browsers Tel and Facetime Audio arbitrary calls CVE-2014-7306 - Atomic Lite Tel, FaceTime and FaceTime Audio arbitrary calls