ZeroHour

CVE-2016-1622

CVSS 3.0
8.8 high
EPSS
1%p69
Published
()
Modified
Description

The Extensions subsystem in Google Chrome before 48.0.2564.109 does not prevent use of the Object.defineProperty method to override intended extension behavior, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code.

Vendors
googledebianopensuse
Products
chrome, debian linux, opensuse
Weakness
CWE-264
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.