The Extensions subsystem in Google Chrome before 49.0.2623.75 does not properly maintain own properties, which allows remote attackers to bypass intended access restrictions via crafted JavaScript code that triggers an incorrect cast, related to extensions/renderer/v8_helpers.h and gin/converter.h.
References
Configurations
Information
Published : 2016-03-05 18:59
Updated : 2016-12-02 19:21
NVD link : CVE-2016-1632
Mitre link : CVE-2016-1632
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
- chrome