Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2017-15394 — Demonstrates an IDN homograph attack in Chromium extensions to spoof URLs, aiding in deception attacks by coercing victims into granting permissions to unexpected domains. | Kitploit
Tools/GitHubGitHub/sudosammy/cve-2017-15394
ExploitationPhishingWeb SecuritySocial EngineeringLearning & Education
GitHubsudosammy/cve-2017-15394

CVE-2017-15394

Demonstrates an IDN homograph attack in Chromium extensions to spoof URLs, aiding in deception attacks by coercing victims into granting permissions to unexpected domains.

View Repository
38 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2017-15394

A URL spoofing flaw has been found in the extensions UI of the Chromium browser < 62.0.3202.62.

An IDN homograph attack demo in Chromium through extensions.

  1. Load unpacked extension into Chrome
  2. View extension details and observe lack of punycode

Impact

An attacker would leverage this weakness to aid in deception attacks by coercing a victim into granting the extension permissions to an unexpected domain.

Patch

Released October 17, 2017: https://chromereleases.googleblog.com/2017/10/stable-channel-update-for-desktop.html

Download Tool