CVE-2016-1658
Published: 18 April 2016
The Extensions subsystem in Google Chrome before 50.0.2661.75 incorrectly relies on GetOrigin method calls for origin comparisons, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted extension.
Priority
CVSS 3 base score: 4.3
Status
Package | Release | Status |
---|---|---|
chromium-browser Launchpad, Ubuntu, Debian |
upstream |
Released
(50.0.2661.75)
|
precise |
Ignored
|
|
trusty |
Does not exist
(trusty was released [50.0.2661.102-0ubuntu0.14.04.1.1117])
|
|
wily |
Released
(50.0.2661.102-0ubuntu0.15.10.1.1227)
|
|
xenial |
Released
(50.0.2661.102-0ubuntu0.16.04.1.1237)
|
|
oxide-qt Launchpad, Ubuntu, Debian |
upstream |
Not vulnerable
|
precise |
Does not exist
|
|
trusty |
Does not exist
(trusty was not-affected)
|
|
wily |
Not vulnerable
|
|
xenial |
Not vulnerable
|