Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

L33Terally

#41979de 53,633
6.5CVSS total
Vulnerabilidades · 1
PT-2016-6280
6.5
2016-08-31
Google · Google Chrome · CVE-2016-5160
**Name of the Vulnerable Software and Affected Versions** Google Chrome versions prior to 53.0.2785.89 on Windows and OS X Google Chrome versions prior to 53.0.2785.92 on Linux **Description** The issue arises from the improper use of an extension's manifest.json web accessible resources field for restrictions on IFRAME elements by the `AllowCrossRendererResourceLoad` function. This makes it easier for remote attackers to conduct clickjacking attacks and trick users into changing extension settings via a crafted web site. **Recommendations** For Google Chrome versions prior to 53.0.2785.89 on Windows and OS X, update to version 53.0.2785.89 or later. For Google Chrome versions prior to 53.0.2785.92 on Linux, update to version 53.0.2785.92 or later. As a temporary workaround, consider restricting access to the `web accessible resources` field in the extension's manifest.json file to minimize the risk of exploitation.