Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:28955
HistoryJan 11, 2021 - 8:09 p.m.

Sandbox Restrictions Bypass

2021-01-1120:09:13
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
18
chromium
sandbox bypass
policy enforcement
webui
malicious extension

EPSS

0.002

Percentile

56.2%

chromium is vulnerable to sandbox restrictions bypass. Insufficient policy enforcement in WebUI allows an attacker who has tricked a user into installing a malicious extension to perform a sandbox escape via a malicious Chrome Extension.