CVE-2016-5132
published 2016-07-23CVE-2016-5132: The Service Workers subsystem in Google Chrome before 52.0.2743.82 does not properly implement the Secure Contexts specification during decisions about whether…
PriorityP342high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
1.47%
71.1th percentile
The Service Workers subsystem in Google Chrome before 52.0.2743.82 does not properly implement the Secure Contexts specification during decisions about whether to control a subframe, which allows remote attackers to bypass the Same Origin Policy via an https IFRAME element inside an http IFRAME element.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | <= 51.0.2704.106 | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Oxide vulnerabilities
vendor_ubuntu·2016-08-05·CVSS 8.8
CVE-2016-1705 [HIGH] Oxide vulnerabilities
Title: Oxide vulnerabilities
Summary: Several security issues were fixed in Oxide.
Multiple security issues were discovered in Chromium. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to read uninitialized memory, cause a denial
of service (application crash) or execute arbitrary code. (CVE-2016-1705)
It was discovered that the PPAPI implementation does not validate the
origin of IPC messages to the plugin broker process. A remote attacker
could potentially exploit this to bypass sandbox protection mechanisms.
(CVE-2016-1706)
It was discovered that Blink does not prevent window creation by a
deferred frame. A remote attacker could potentially exploit this to bypass
same origin restrictions. (CVE-2016-1710)
It was discovere
Red Hat
chromium-browser: limited same-origin bypass in service workers
vendor_redhat·2016-07-20·CVSS 8.8
CVE-2016-5132 [HIGH] chromium-browser: limited same-origin bypass in service workers
chromium-browser: limited same-origin bypass in service workers
The Service Workers subsystem in Google Chrome before 52.0.2743.82 does not properly implement the Secure Contexts specification during decisions about whether to control a subframe, which allows remote attackers to bypass the Same Origin Policy via an https IFRAME element inside an http IFRAME element.
GHSA
GHSA-682g-9hxq-jvvv: The Service Workers subsystem in Google Chrome before 52
ghsa_unreviewed·2022-05-17
CVE-2016-5132 [HIGH] GHSA-682g-9hxq-jvvv: The Service Workers subsystem in Google Chrome before 52
The Service Workers subsystem in Google Chrome before 52.0.2743.82 does not properly implement the Secure Contexts specification during decisions about whether to control a subframe, which allows remote attackers to bypass the Same Origin Policy via an https IFRAME element inside an http IFRAME element.
OSV
oxide-qt vulnerabilities
osv·2016-08-05·CVSS 8.8
CVE-2016-1705 [HIGH] oxide-qt vulnerabilities
oxide-qt vulnerabilities
Multiple security issues were discovered in Chromium. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to read uninitialized memory, cause a denial
of service (application crash) or execute arbitrary code. (CVE-2016-1705)
It was discovered that the PPAPI implementation does not validate the
origin of IPC messages to the plugin broker process. A remote attacker
could potentially exploit this to bypass sandbox protection mechanisms.
(CVE-2016-1706)
It was discovered that Blink does not prevent window creation by a
deferred frame. A remote attacker could potentially exploit this to bypass
same origin restrictions. (CVE-2016-1710)
It was discovered that Blink does not disable frame navigation during a
det
OSV
CVE-2016-5132: The Service Workers subsystem in Google Chrome before 52
osv·2016-07-23·CVSS 8.8
CVE-2016-5132 [HIGH] CVE-2016-5132: The Service Workers subsystem in Google Chrome before 52
The Service Workers subsystem in Google Chrome before 52.0.2743.82 does not properly implement the Secure Contexts specification during decisions about whether to control a subframe, which allows remote attackers to bypass the Same Origin Policy via an https IFRAME element inside an http IFRAME element.
No detection rules found.
No public exploits indexed.
http://googlechromereleases.blogspot.com/2016/07/stable-channel-update.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00022.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00028.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1485.htmlhttp://www.debian.org/security/2016/dsa-3637http://www.securityfocus.com/bid/92053http://www.securitytracker.com/id/1036428http://www.ubuntu.com/usn/USN-3041-1https://codereview.chromium.org/2009453002https://codereview.chromium.org/2061203002/https://codereview.chromium.org/2071433003https://codereview.chromium.org/2082493002/https://codereview.chromium.org/2085923002https://crbug.com/607543https://security.gentoo.org/glsa/201610-09http://googlechromereleases.blogspot.com/2016/07/stable-channel-update.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00022.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00028.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1485.htmlhttp://www.debian.org/security/2016/dsa-3637http://www.securityfocus.com/bid/92053http://www.securitytracker.com/id/1036428http://www.ubuntu.com/usn/USN-3041-1https://codereview.chromium.org/2009453002https://codereview.chromium.org/2061203002/https://codereview.chromium.org/2071433003https://codereview.chromium.org/2082493002/https://codereview.chromium.org/2085923002https://crbug.com/607543https://security.gentoo.org/glsa/201610-09
2016-07-23
Published