cbcvebase.
CVE-2016-5173
published 2016-09-25

CVE-2016-5173: The extensions subsystem in Google Chrome before 53.0.2785.113 does not properly restrict access to Object.prototype, which allows remote attackers to load…

PriorityP430high7.1CVSS 3.0
AVNACLPRNUIRSCCLILAL
EPSS
1.02%
60.0th percentile
The extensions subsystem in Google Chrome before 53.0.2785.113 does not properly restrict access to Object.prototype, which allows remote attackers to load unintended resources, and consequently trigger unintended JavaScript function calls and bypass the Same Origin Policy via an indirect interception attack.

Affected

1 ranges
VendorProductVersion rangeFixed in
googlechrome<= 53.0.2785.101

CVSS provenance

nvdv3.07.1HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.