5.3
CVSSv3

CVE-2016-1692

Published: 05/06/2016 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

WebKit/Source/core/css/StyleSheetContents.cpp in Blink, as used in Google Chrome prior to 51.0.2704.63, permits cross-origin loading of CSS stylesheets by a ServiceWorker even when the stylesheet download has an incorrect MIME type, which allows remote malicious users to bypass the Same Origin Policy via a crafted web site.

Vulnerable Product Search on Vulmon Subscribe to Product

debian debian linux 8.0

canonical ubuntu linux 16.04

canonical ubuntu linux 15.10

redhat enterprise linux desktop 6.0

canonical ubuntu linux 14.04

redhat enterprise linux server 6.0

redhat enterprise linux workstation 6.0

suse linux enterprise 12.0

opensuse leap 42.1

opensuse opensuse 13.2

google chrome

Vendor Advisories

Several security issues were fixed in Oxide ...
WebKit/Source/core/css/StyleSheetContentscpp in Blink, as used in Google Chrome before 510270463, permits cross-origin loading of CSS stylesheets by a ServiceWorker even when the stylesheet download has an incorrect MIME type, which allows remote attackers to bypass the Same Origin Policy via a crafted web site ...