Google Chrome Frame Same Origin Policy Bypass Vulnerability
BID:37067
Info
Google Chrome Frame Same Origin Policy Bypass Vulnerability
| Bugtraq ID: | 37067 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 18 2009 12:00AM |
| Updated: | Nov 19 2009 03:15PM |
| Credit: | Lostmon, Billy Rios and Microsoft Vulnerability Research (MSVR) |
| Vulnerable: |
Google Chrome Frame 4.0.223.9 |
| Not Vulnerable: |
Google Chrome Frame 4.0.245.1 |
Discussion
Google Chrome Frame Same Origin Policy Bypass Vulnerability
Google Chrome Frame is prone to a vulnerability that allows attackers to bypass the same-origin policy.
Attackers may exploit this issue to violate the same-origin policy and perform actions with elevated privileges. Other attacks may also be possible.
Google Chrome Frame 4.0.223.9 and earlier versions are affected.
Google Chrome Frame is prone to a vulnerability that allows attackers to bypass the same-origin policy.
Attackers may exploit this issue to violate the same-origin policy and perform actions with elevated privileges. Other attacks may also be possible.
Google Chrome Frame 4.0.223.9 and earlier versions are affected.
Exploit / POC
Google Chrome Frame Same Origin Policy Bypass Vulnerability
To exploit this issue, an attacker must entice a victim to follow a malicious URL.
To exploit this issue, an attacker must entice a victim to follow a malicious URL.
Solution / Fix
Google Chrome Frame Same Origin Policy Bypass Vulnerability
Solution:
The vendor has released updates. Please see the references for details.
Solution:
The vendor has released updates. Please see the references for details.
References
Google Chrome Frame Same Origin Policy Bypass Vulnerability
References:
References:
- Google Chrome Frame Homepage (Google)
- Google Chrome Frame null domain XSS (Lostmon)
- Google Chrome Frame Update: Bug Fixes (Google)