The FrameLoader::startLoad function in WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 51.0.2704.79, does not prevent frame navigations during DocumentLoader detach operations, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code.
                
            References
                    | Link | Resource | 
|---|---|
| http://googlechromereleases.blogspot.com/2016/06/stable-channel-update.html | Vendor Advisory | 
| https://codereview.chromium.org/2021373003 | Issue Tracking | 
| https://crbug.com/613266 | Permissions Required | 
| http://www.ubuntu.com/usn/USN-2992-1 | Third Party Advisory | 
| https://access.redhat.com/errata/RHSA-2016:1201 | Third Party Advisory | 
| http://www.securitytracker.com/id/1036026 | Third Party Advisory | 
| http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00005.html | Third Party Advisory | 
| http://www.debian.org/security/2016/dsa-3594 | Third Party Advisory | 
| http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00004.html | Third Party Advisory | 
| http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00003.html | Third Party Advisory | 
Configurations
                    Configuration 1 (hide)
| 
 | 
Configuration 2 (hide)
| 
 | 
Information
                Published : 2016-06-05 16:59
Updated : 2018-10-30 09:27
NVD link : CVE-2016-1697
Mitre link : CVE-2016-1697
JSON object : View
CWE
                
                    
                        
                        CWE-284
                        
            Improper Access Control
Products Affected
                redhat
- enterprise_linux_desktop
- enterprise_linux_workstation
- enterprise_linux_server
- chrome
suse
- linux_enterprise
canonical
- ubuntu_linux
opensuse
- leap
- opensuse
debian
- debian_linux


