Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

L33Terally

#43619of 56,330
6.5Total CVSS
Vulnerabilities · 1
PT-2016-6280
6.5
2016-08-31
Google · Google Chrome · CVE-2016-5160
**Name of the Vulnerable Software and Affected Versions** Google Chrome versions prior to 53.0.2785.89 on Windows and OS X Google Chrome versions prior to 53.0.2785.92 on Linux **Description** The issue arises from the improper use of an extension's manifest.json web accessible resources field for restrictions on IFRAME elements by the `AllowCrossRendererResourceLoad` function. This makes it easier for remote attackers to conduct clickjacking attacks and trick users into changing extension settings via a crafted web site. **Recommendations** For Google Chrome versions prior to 53.0.2785.89 on Windows and OS X, update to version 53.0.2785.89 or later. For Google Chrome versions prior to 53.0.2785.92 on Linux, update to version 53.0.2785.92 or later. As a temporary workaround, consider restricting access to the `web accessible resources` field in the extension's manifest.json file to minimize the risk of exploitation.