Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gj69-jhg9-8m88

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.6

Описание

The implementation of the Page.downloadBehavior backend unconditionally marked downloaded files as safe, regardless of file type in Google Chrome prior to 66.0.3359.117 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted HTML page and user interaction.

The implementation of the Page.downloadBehavior backend unconditionally marked downloaded files as safe, regardless of file type in Google Chrome prior to 66.0.3359.117 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted HTML page and user interaction.

EPSS

Процентиль: 75%
0.00864
Низкий

9.6 Critical

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 9.6
ubuntu
около 7 лет назад

The implementation of the Page.downloadBehavior backend unconditionally marked downloaded files as safe, regardless of file type in Google Chrome prior to 66.0.3359.117 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted HTML page and user interaction.

CVSS3: 6.5
redhat
больше 7 лет назад

The implementation of the Page.downloadBehavior backend unconditionally marked downloaded files as safe, regardless of file type in Google Chrome prior to 66.0.3359.117 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted HTML page and user interaction.

CVSS3: 9.6
nvd
около 7 лет назад

The implementation of the Page.downloadBehavior backend unconditionally marked downloaded files as safe, regardless of file type in Google Chrome prior to 66.0.3359.117 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted HTML page and user interaction.

CVSS3: 9.6
debian
около 7 лет назад

The implementation of the Page.downloadBehavior backend unconditionall ...

CVSS3: 9.6
fstec
почти 8 лет назад

Уязвимость реализации бэкэнда Page.downloadBehavior браузера Google Chrome, позволяющая нарушителю убедить пользователя установить вредоносное расширение

EPSS

Процентиль: 75%
0.00864
Низкий

9.6 Critical

CVSS3

Дефекты

CWE-434