Related Vulnerabilities: CVE-2017-2445  

An issue has been found in WebKit, allowing remote attackers to conduct Universal XSS (UXSS) attacks via crafted frame objects.

Severity High

Remote Yes

Type Cross-site scripting

Description

An issue has been found in WebKit, allowing remote attackers to conduct Universal XSS (UXSS) attacks via crafted frame objects.

AVG-234 webkitgtk, webkitgtk2 2.4.11-6 Critical Unknown

AVG-235 webkit2gtk 2.14.5-1 2.16.1-1 Critical Fixed

28 Apr 2017 ASA-201704-9 AVG-235 webkit2gtk Critical multiple issues

https://webkitgtk.org/security/WSA-2017-0003.html