CVE-2016-1622
published 2016-02-14CVE-2016-1622: The Extensions subsystem in Google Chrome before 48.0.2564.109 does not prevent use of the Object.defineProperty method to override intended extension…
PriorityP339high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
1.32%
67.4th percentile
The Extensions subsystem in Google Chrome before 48.0.2564.109 does not prevent use of the Object.defineProperty method to override intended extension behavior, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| chrome | <= 48.0.2564.103 | — | |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
chromium-browser: same-origin bypass in Extensions
vendor_redhat·2016-02-09·CVSS 8.8
CVE-2016-1622 [HIGH] chromium-browser: same-origin bypass in Extensions
chromium-browser: same-origin bypass in Extensions
The Extensions subsystem in Google Chrome before 48.0.2564.109 does not prevent use of the Object.defineProperty method to override intended extension behavior, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code.
GHSA
GHSA-4h9w-599p-58j9: The Extensions subsystem in Google Chrome before 48
ghsa_unreviewed·2022-05-14
CVE-2016-1622 [HIGH] GHSA-4h9w-599p-58j9: The Extensions subsystem in Google Chrome before 48
The Extensions subsystem in Google Chrome before 48.0.2564.109 does not prevent use of the Object.defineProperty method to override intended extension behavior, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code.
OSV
CVE-2016-1622: The Extensions subsystem in Google Chrome before 48
osv·2016-02-14·CVSS 8.8
CVE-2016-1622 [HIGH] CVE-2016-1622: The Extensions subsystem in Google Chrome before 48
The Extensions subsystem in Google Chrome before 48.0.2564.109 does not prevent use of the Object.defineProperty method to override intended extension behavior, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code.
No detection rules found.
No public exploits indexed.
http://googlechromereleases.blogspot.com/2016/02/stable-channel-update_9.htmlhttp://lists.opensuse.org/opensuse-updates/2016-02/msg00104.htmlhttp://lists.opensuse.org/opensuse-updates/2016-02/msg00119.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0241.htmlhttp://www.debian.org/security/2016/dsa-3486http://www.securityfocus.com/bid/83125http://www.securitytracker.com/id/1035183https://code.google.com/p/chromium/issues/detail?id=546677https://codereview.chromium.org/1417513003https://security.gentoo.org/glsa/201603-09http://googlechromereleases.blogspot.com/2016/02/stable-channel-update_9.htmlhttp://lists.opensuse.org/opensuse-updates/2016-02/msg00104.htmlhttp://lists.opensuse.org/opensuse-updates/2016-02/msg00119.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0241.htmlhttp://www.debian.org/security/2016/dsa-3486http://www.securityfocus.com/bid/83125http://www.securitytracker.com/id/1035183https://code.google.com/p/chromium/issues/detail?id=546677https://codereview.chromium.org/1417513003https://security.gentoo.org/glsa/201603-09
2016-02-14
Published