CVE-2016-5132
CVE-2016-5132
The Service Workers subsystem in Google Chrome before 52.0.2743.82 does not properly implement the Secure Contexts specification during decisions about whether to control a subframe, which allows remote attackers to bypass the Same Origin Policy via an https IFRAME element inside an http IFRAME element.
Produtos afetados
n/a · n/aQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://googlechromereleases.blogspot.com/2016/07/stable-channel-update.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00022.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00028.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1485.htmlhttps://codereview.chromium.org/2009453002https://codereview.chromium.org/2061203002/https://codereview.chromium.org/2071433003https://codereview.chromium.org/2082493002/https://codereview.chromium.org/2085923002https://crbug.com/607543