Back to search
CVE-2016-5173
Published: Sep 25, 2016
Modified: Aug 6, 2024
PUBLISHED
Description
The extensions subsystem in Google Chrome before 53.0.2785.113 does not properly restrict access to Object.prototype, which allows remote attackers to load unintended resources, and consequently trigger unintended JavaScript function calls and bypass the Same Origin Policy via an indirect interception attack.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
DSA-3667
vendor-advisory
x_refsource_DEBIAN
https://codereview.chromium.org/1840453002
x_refsource_CONFIRM
1036826
vdb-entry
x_refsource_SECTRACK
92942
vdb-entry
x_refsource_BID
https://crbug.com/468931
x_refsource_CONFIRM
https://crbug.com/497507
x_refsource_MISC
GLSA-201610-09
vendor-advisory
x_refsource_GENTOO
RHSA-2016:1905
vendor-advisory
x_refsource_REDHAT
https://crbug.com/471523
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now