Google Chrome same-Source Policy Bypass Vulnerability (CVE-2015-1302)
Google Chrome same-Source Policy Bypass Vulnerability (CVE-2015-1302)
Release date:
Updated on:
Affected Systems:
Google Chrome < 46.0.2490.86
Description:
CVE (CAN) ID: CVE-2015-1302
Google Chrome is a Web browser tool developed by Google.
In versions earlier than Google Chrome 46.0.2490.86, the ghost browser does not properly restrict access to script messages and APIs. Remote attackers can exploit this vulnerability to bypass the same-origin policy.
<* Source: Google
*>
Suggestion:
Vendor patch:
Google
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://code.google.com/p/chromium/issues/detail? Id = 520422
Http://googlechromereleases.blogspot.com/2015/11/stable-channel-update.html
Https://codereview.chromium.org/1316803003
Install Google Chrome in Ubuntu 14.04 LTS
Solution to Chrome dependency installation in Ubuntu 13.04
Install Chrome in openSUSE
Install Google Chrome 35 Beta for Linux Users
Install Google Chrome in CentOS 6.x
Chrome details: click here
Chrome: click here
This article permanently updates the link address: