Google Chrome CVE-2016-1623 Weak Authentication Vulnerability

description-logoDescription

The DOM implementation in Google Chrome before 48.0.2564.109 does not properly restrict frame-attach operations from occurring during or after frame-detach operations, which allows remote attackers to bypass the Same Origin Policy via a crafted web site, related to FrameLoader.cpp, HTMLFrameOwnerElement.h, LocalFrame.cpp, and WebLocalFrameImpl.cpp.

affected-products-logoAffected Applications

Google Chrome

CVE References

CVE-2016-1623