Vulnerability Name: | CVE-2016-1622 (CCN-110515) | ||||||||||||||||||||||||||||
Assigned: | 2016-02-09 | ||||||||||||||||||||||||||||
Published: | 2016-02-09 | ||||||||||||||||||||||||||||
Updated: | 2018-10-30 | ||||||||||||||||||||||||||||
Summary: | The Extensions subsystem in Google Chrome before 48.0.2564.109 does not prevent use of the Object.defineProperty method to override intended extension behavior, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code. | ||||||||||||||||||||||||||||
CVSS v3 Severity: | 8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) 7.7 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
3.8 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
| ||||||||||||||||||||||||||||
Vulnerability Type: | CWE-264 | ||||||||||||||||||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2016-1622 Source: CCN Type: Google Chrome Releases Web site Stable Channel Update Source: CONFIRM Type: Patch, Vendor Advisory http://googlechromereleases.blogspot.com/2016/02/stable-channel-update_9.html Source: SUSE Type: UNKNOWN openSUSE-SU-2016:0491 Source: SUSE Type: Third Party Advisory openSUSE-SU-2016:0518 Source: CCN Type: RHSA-2016-0241 Important: chromium-browser security update Source: REDHAT Type: UNKNOWN RHSA-2016:0241 Source: DEBIAN Type: Third Party Advisory DSA-3486 Source: BID Type: UNKNOWN 83125 Source: CCN Type: BID-83125 Google Chrome Prior to 48.0.2564.109 Multiple Security Vulnerabilities Source: SECTRACK Type: UNKNOWN 1035183 Source: CONFIRM Type: Permissions Required https://code.google.com/p/chromium/issues/detail?id=546677 Source: CONFIRM Type: Patch https://codereview.chromium.org/1417513003 Source: XF Type: UNKNOWN google-chrome-cve20161622-sec-bypass(110515) Source: GENTOO Type: UNKNOWN GLSA-201603-09 Source: CCN Type: WhiteSource Vulnerability Database CVE-2016-1622 | ||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Configuration RedHat 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||
BACK |