Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j2m6-qgr7-3354

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information via a crafted Chrome Extension.

Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information via a crafted Chrome Extension.

EPSS

Процентиль: 75%
0.00883
Низкий

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 5 лет назад

Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information via a crafted Chrome Extension.

CVSS3: 6.5
redhat
больше 5 лет назад

Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information via a crafted Chrome Extension.

CVSS3: 4.3
nvd
больше 5 лет назад

Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information via a crafted Chrome Extension.

CVSS3: 4.3
debian
больше 5 лет назад

Insufficient policy enforcement in extensions in Google Chrome prior t ...

CVSS3: 5.3
fstec
больше 5 лет назад

Уязвимость расширений браузера Google Chrome, связанная с недостатками разграничения доступа к некоторым функциям, позволяющая нарушителю получить доступ к конфиденциальным данным

EPSS

Процентиль: 75%
0.00883
Низкий