Google Chrome CSP protection mechanism Bypass Vulnerability (CVE-2016-5135)
Google Chrome CSP protection mechanism Bypass Vulnerability (CVE-2016-5135)
Release date:
Updated on:
Affected Systems:
Google Chrome <52.0.2743.82
Description:
CVE (CAN) ID: CVE-2016-5135
Google Chrome is a Web browser tool developed by Google.
Google Chrome versions earlier than <52.0.2743.82, Blink/WebKit/Source/core/html/parser/htmlpreload.pdf. cpp does not take into account the referrer-policy information of the HTML document during the preload request process. This allows remote attackers to bypass the CSP protection mechanism.
<* Source: Google
*>
Suggestion:
Vendor patch:
Google
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://codereview.chromium.org/1913983002
Http://googlechromereleases.blogspot.com/2016/07/stable-channel-update.html
This article permanently updates the link address: