CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
Percentile
84.8%
The WebRequest API implementation in
extensions/browser/api/web_request/web_request_api.cc in Google Chrome
before 45.0.2454.85 does not properly consider a request’s source before
accepting the request, which allows remote attackers to bypass intended
access restrictions via a crafted (1) app or (2) extension.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
ubuntu | 14.04 | noarch | chromium-browser | < 45.0.2454.85-0ubuntu0.14.04.1.1097 | UNKNOWN |
ubuntu | 15.04 | noarch | chromium-browser | < 45.0.2454.85-0ubuntu0.15.04.1.1181 | UNKNOWN |
ubuntu | 15.10 | noarch | chromium-browser | < 45.0.2454.85-0ubuntu1.1198 | UNKNOWN |