Vulnerability CVE-2016-1623: Information

Description

The DOM implementation in Google Chrome before 48.0.2564.109 does not properly restrict frame-attach operations from occurring during or after frame-detach operations, which allows remote attackers to bypass the Same Origin Policy via a crafted web site, related to FrameLoader.cpp, HTMLFrameOwnerElement.h, LocalFrame.cpp, and WebLocalFrameImpl.cpp.

Severity: HIGH (8.8) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Published: Feb. 14, 2016
Modified: Nov. 7, 2023
Error type identifier: CWE-264

Fixed packages

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

      Configuration 2

      cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
      End including
      48.0.2564.103

      Configuration 3

      cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*