CVE-2016-1697 PUBLISHED

The FrameLoader::startLoad function in WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 51.0.2704.79, does not prevent frame navigations during DocumentLoader detach operations, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code.

EPSS 1.84% · 82.8th percentile

Risk Scores

EPSS Score
1.84%
82.8th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSchromium-browser0, 50.0.2661.102-0ubuntu0.16.04.1.1237, 49.0.2623.108-0ubuntu1.1233
Ubuntu:16.04:LTSoxide-qt1.11.3-0ubuntu3, 1.10.3-0ubuntu0.15.10.2, 1.10.3-0ubuntu0.15.10.1
Ubuntu:14.04:LTSoxide-qt1.11.3-0ubuntu0.14.04.1, 1.0.0~bzr501-0ubuntu1, 1.0.0~bzr501-0ubuntu2
Ubuntu:14.04:LTSchromium-browser49.0.2623.87-0ubuntu0.14.04.1.1112, 49.0.2623.108-0ubuntu0.14.04.1.1113, 50.0.2661.102-0ubuntu0.14.04.1.1117

Timeline

References

Open in Interactive Console →