Same Origin Policy bypass vulnerability in the DOM implementation in Google Chrome via crafted web site (rpm)ID: oval:org.secpod.oval:def:32950 | Date: (C)2016-02-16 (M)2022-06-24 |
Class: VULNERABILITY | Family: unix |
The host is installed with Google Chrome before 48.0.2564.109 and is prone to a same origin policy bypass vulnerability. The flaw is present in the application, which fails to handle crafted web site, related to FrameLoader.cpp. Successful exploitation allows remote attackers to bypass the same origin policy.