CVE-2017-15430: Google Chrome

Medium severity, CVSS 4.3. EPSS: 0.5% chance of exploitation in the next 30 days.

Insufficient data validation in Chromecast plugin in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.

Affected products

  • Google Chrome: before 63.0.3239.84 (fixed in 63.0.3239.84)

Published 2018-08-28. Last modified 2026-06-17.