PT-2019-8019 · Google · Google Chrome

Publicado

2019-01-09

·

Atualizado

2019-01-30

·

CVE-2017-15402

CVSS v3.1

9.6

Crítica

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Google Chrome on Chrome OS versions prior to 62.0.3202.74
Description The issue allows a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. This is possible because a compromised renderer can control an ID to overwrite the page state of any other frame in the same process in Navigation.
Recommendations For versions prior to 62.0.3202.74, update to version 62.0.3202.74 or later to resolve the issue.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-15402

Produtos afetados

Google Chrome