Candidate: CVE-2017-15402 PublicDate: 2019-01-09 19:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15402 https://chromereleases.googleblog.com/2017/10/stable-channel-update-for-chrome-os_27.html https://crbug.com/766262 Description: Using an ID that can be controlled by a compromised renderer which allows any frame to overwrite the page_state of any other frame in the same process in Navigation in Google Chrome on Chrome OS prior to 62.0.3202.74 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. Ubuntu-Description: Notes: mdeslaur> chrome os specific Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H [9.6 CRITICAL] Patches_chromium-browser: upstream_chromium-browser: released precise/esm_chromium-browser: DNE trusty_chromium-browser: ignored (no longer updated) trusty/esm_chromium-browser: DNE (trusty was ignored [no longer updated]) xenial_chromium-browser: not-affected bionic_chromium-browser: not-affected cosmic_chromium-browser: ignored (reached end-of-life) disco_chromium-browser: ignored (reached end-of-life) eoan_chromium-browser: not-affected devel_chromium-browser: not-affected