Insufficient data validation in Chromecast plugin in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-15430.json"
[ { "events": [ { "introduced": "0" }, { "fixed": "63.0.3239.84" } ] } ]