Insufficient policy enforcement during navigation between different schemes in Google Chrome prior to 60.0.3112.78 for Android allowed a remote attacker to perform cross origin content download via a crafted HTML page, related to intents.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-5096.json"
[ { "events": [ { "introduced": "0" }, { "fixed": "60.0.3112.78" } ] } ]