PT-2019-8019 · Google · Google Chrome

Published

2019-01-09

·

Updated

2019-01-30

·

CVE-2017-15402

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Google Chrome on Chrome OS versions prior to 62.0.3202.74
Description The issue allows a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. This is possible because a compromised renderer can control an ID to overwrite the page state of any other frame in the same process in Navigation.
Recommendations For versions prior to 62.0.3202.74, update to version 62.0.3202.74 or later to resolve the issue.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-15402

Affected Products

Google Chrome