Описание
The extensions subsystem in Google Chrome before 53.0.2785.113 does not properly restrict access to Object.prototype, which allows remote attackers to load unintended resources, and consequently trigger unintended JavaScript function calls and bypass the Same Origin Policy via an indirect interception attack.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | released | 53.0.2785.143-0ubuntu1.1307 |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was released [53.0.2785.143-0ubuntu0.14.04.1.1142]] |
| precise | ignored | |
| trusty | released | 53.0.2785.143-0ubuntu0.14.04.1.1142 |
| trusty/esm | DNE | trusty was released [53.0.2785.143-0ubuntu0.14.04.1.1142] |
| upstream | released | 53.0.2785.113 |
| vivid/stable-phone-overlay | DNE | |
| vivid/ubuntu-core | DNE | |
| xenial | released | 53.0.2785.143-0ubuntu0.16.04.1.1254 |
| yakkety | released | 53.0.2785.143-0ubuntu1.1307 |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was not-affected] |
| esm-infra/xenial | not-affected | |
| precise | DNE | |
| trusty | not-affected | |
| trusty/esm | DNE | trusty was not-affected |
| upstream | not-affected | |
| vivid/stable-phone-overlay | not-affected | |
| vivid/ubuntu-core | DNE | |
| xenial | not-affected |
Показывать по
6.8 Medium
CVSS2
7.1 High
CVSS3
Связанные уязвимости
The extensions subsystem in Google Chrome before 53.0.2785.113 does not properly restrict access to Object.prototype, which allows remote attackers to load unintended resources, and consequently trigger unintended JavaScript function calls and bypass the Same Origin Policy via an indirect interception attack.
The extensions subsystem in Google Chrome before 53.0.2785.113 does not properly restrict access to Object.prototype, which allows remote attackers to load unintended resources, and consequently trigger unintended JavaScript function calls and bypass the Same Origin Policy via an indirect interception attack.
The extensions subsystem in Google Chrome before 53.0.2785.113 does no ...
The extensions subsystem in Google Chrome before 53.0.2785.113 does not properly restrict access to Object.prototype, which allows remote attackers to load unintended resources, and consequently trigger unintended JavaScript function calls and bypass the Same Origin Policy via an indirect interception attack.
6.8 Medium
CVSS2
7.1 High
CVSS3