CVE-2016-1710 PUBLISHED

The ChromeClientImpl::createWindow method in WebKit/Source/web/ChromeClientImpl.cpp in Blink, as used in Google Chrome before 52.0.2743.82, does not prevent window creation by a deferred frame, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.

EPSS 1.28% · 79.5th percentile

Risk Scores

EPSS Score
1.28%
79.5th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSchromium-browser37.0.2062.120-0ubuntu0.14.04.1~pkg1049, 38.0.2125.111-0ubuntu0.14.04.1.1061, 39.0.2171.65-0ubuntu0.14.04.1.1064
Ubuntu:14.04:LTSoxide-qt1.12.6-0ubuntu0.14.04.1, 1.12.7-0ubuntu0.14.04.1, 1.13.6-0ubuntu0.14.04.1
Ubuntu:16.04:LTSoxide-qt1.15.8-0ubuntu0.16.04.1, 1.11.3-0ubuntu3, 1.11.4-0ubuntu1
Ubuntu:16.04:LTSchromium-browser45.0.2454.101-0ubuntu1.1201, 47.0.2526.73-0ubuntu1.1218, 47.0.2526.106-0ubuntu1.1221

Timeline

References

Open in Interactive Console →