### [CVE-2014-3187](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3187) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen) ### Description Google Chrome before 37.0.2062.60 and 38.x before 38.0.2125.59 on iOS does not properly restrict processing of (1) facetime:// and (2) facetime-audio:// URLs, which allows remote attackers to obtain video and audio data from a device via a crafted web site. ### POC #### Reference - https://medium.com/section-9-lab/abusing-ios-url-handlers-on-messages-96979e8b12f5 #### Github - https://github.com/Section9Labs/advisories