CVE-2016-1622Google Chrome vulnerability

CWE-2646 documents5 sources
Severity
8.8HIGHNVD
EPSS
1.5%
top 18.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 14
Latest updateMay 14

Description

The Extensions subsystem in Google Chrome before 48.0.2564.109 does not prevent use of the Object.defineProperty method to override intended extension behavior, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

NVDgoogle/chrome48.0.2564.103

Also affects: Debian Linux 8.0

🔴Vulnerability Details

2
GHSA
GHSA-4h9w-599p-58j9: The Extensions subsystem in Google Chrome before 482022-05-14
OSV
CVE-2016-1622: The Extensions subsystem in Google Chrome before 482016-02-14

📋Vendor Advisories

1
Red Hat
chromium-browser: same-origin bypass in Extensions2016-02-09

💬Community

1
Bugzilla
CVE-2016-1622 chromium-browser: same-origin bypass in Extensions2016-02-10