ZeroHour

CVE-2016-1676

CVSS 3.0
8.8 high
EPSS
2%p73
Published
()
Modified
Description

extensions/renderer/resources/binding.js in the extension bindings in Google Chrome before 51.0.2704.63 does not properly use prototypes, which allows remote attackers to bypass the Same Origin Policy via unspecified vectors.

Vendors
debianopensuseredhatsusegoogle
Products
debian linux, leap, opensuse, enterprise linux desktop, enterprise linux server, enterprise linux workstation, linux enterprise, chrome
Weakness
CWE-284
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.