Oval Definition:oval:org.cisecurity:def:788
Revision Date:2016-07-15Version:30
Title:Parameter sanitization failure in DevTools - CVE-2016-1699
Description:WebKit/Source/devtools/front_end/devtools.js in the Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 51.0.2704.79, does not ensure that the remoteFrontendUrl parameter is associated with a chrome-devtools-frontend.appspot.com URL, which allows remote attackers to bypass intended access restrictions via a crafted URL.
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2016-1699
http://googlechromereleases.blogspot.com/2016/06/stable-channel-update.html
https://codereview.chromium.org/2010783002
https://crbug.com/607939
CVE-2016-1699
Platform(s):Microsoft Windows 10
Microsoft Windows 7
Microsoft Windows 8
Microsoft Windows 8.1
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Server 2012
Microsoft Windows Server 2012 R2
Microsoft Windows Vista
Product(s):Google Chrome
Definition Synopsis
  • Google Chrome is installed
  • AND Check if Google Chrome version is less than 51.0.2704.79
  • BACK