Sploitus

CVE-2016-1697

1 known exploit for CVE-2016-1697

The FrameLoader::startLoad function in WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 51.0.2704.79, does not prevent frame navigations during DocumentLoader detach operations, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code.

Google Chrome
≤ 51.0.2704.63
Fix
Available
CVSS 3.0
8.8 HIGH
EPSS
2.1% (80th percentile)
Weakness
CWE-284
NVD status
Modified
Published
2016-06-05
CVE-2016-1697 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2016-1697

Proof-of-concept code and exploit modules indexed by Sploitus