Início
Início
Tendências
Tendências
Vulnerabilidades
Vulnerabilidades
Notícias
Notícias
Pesquisadores
Pesquisadores
Por que dbugs?
Por que dbugs?
Configurações

L33Terally

#44127de 56,331
6.5CVSS total
Vulnerabilidades · 1
PT-2016-6280
6.5
2016-08-31
Google · Google Chrome · CVE-2016-5160
**Name of the Vulnerable Software and Affected Versions** Google Chrome versions prior to 53.0.2785.89 on Windows and OS X Google Chrome versions prior to 53.0.2785.92 on Linux **Description** The issue arises from the improper use of an extension's manifest.json web accessible resources field for restrictions on IFRAME elements by the `AllowCrossRendererResourceLoad` function. This makes it easier for remote attackers to conduct clickjacking attacks and trick users into changing extension settings via a crafted web site. **Recommendations** For Google Chrome versions prior to 53.0.2785.89 on Windows and OS X, update to version 53.0.2785.89 or later. For Google Chrome versions prior to 53.0.2785.92 on Linux, update to version 53.0.2785.92 or later. As a temporary workaround, consider restricting access to the `web accessible resources` field in the extension's manifest.json file to minimize the risk of exploitation.