ZeroHour

CVE-2016-1661

CVSS 3.0
8.0 high
EPSS
1%p67
Published
()
Modified
Description

Blink, as used in Google Chrome before 50.0.2661.94, does not ensure that frames satisfy a check for the same renderer process in addition to a Same Origin Policy check, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted web site, related to BindingSecurity.cpp and DOMWindow.cpp.

Vendors
redhatgoogleopensuse
Products
enterprise linux desktop supplementary, enterprise linux server supplementary, enterprise linux server supplementary eus, enterprise linux workstation supplementary, chrome, opensuse
Weakness
CWE-20
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.