Описание
The content renderer client in Google Chrome prior to 54.0.2840.85 for Android insufficiently enforced the Same Origin Policy amongst downloaded files, which allowed a remote attacker to access any downloaded file and interact with sites, including those the user was logged into, via a crafted HTML page.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | android only |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was not-affected [android only]] |
| precise | not-affected | android only |
| trusty | not-affected | android only |
| trusty/esm | DNE | trusty was not-affected [android only] |
| upstream | needs-triage | |
| vivid/stable-phone-overlay | DNE | |
| vivid/ubuntu-core | DNE | |
| xenial | not-affected | android only |
| yakkety | not-affected | android only |
Показывать по
EPSS
6.8 Medium
CVSS2
8.8 High
CVSS3
Связанные уязвимости
The content renderer client in Google Chrome prior to 54.0.2840.85 for Android insufficiently enforced the Same Origin Policy amongst downloaded files, which allowed a remote attacker to access any downloaded file and interact with sites, including those the user was logged into, via a crafted HTML page.
The content renderer client in Google Chrome prior to 54.0.2840.85 for ...
The content renderer client in Google Chrome prior to 54.0.2840.85 for Android insufficiently enforced the Same Origin Policy amongst downloaded files, which allowed a remote attacker to access any downloaded file and interact with sites, including those the user was logged into, via a crafted HTML page.
Уязвимость браузера Google Chrome, позволяющая нарушителю нарушить конфиденциальность, целостность и доступность защищаемой информации
EPSS
6.8 Medium
CVSS2
8.8 High
CVSS3