CVE Database
/

CVE-2016-5173

Back to search

CVE-2016-5173

Published: Sep 25, 2016

Modified: Aug 6, 2024

PUBLISHED

Description

The extensions subsystem in Google Chrome before 53.0.2785.113 does not properly restrict access to Object.prototype, which allows remote attackers to load unintended resources, and consequently trigger unintended JavaScript function calls and bypass the Same Origin Policy via an indirect interception attack.

VendorProductVersions

n/a

n/a

affected
n/a

References

DSA-3667
vendor-advisory
x_refsource_DEBIAN
1036826
vdb-entry
x_refsource_SECTRACK
92942
vdb-entry
x_refsource_BID
https://crbug.com/468931
x_refsource_CONFIRM
https://crbug.com/497507
x_refsource_MISC
GLSA-201610-09
vendor-advisory
x_refsource_GENTOO
RHSA-2016:1905
vendor-advisory
x_refsource_REDHAT
https://crbug.com/471523
x_refsource_MISC

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now