The Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome prior to 52.0.2743.116, mishandles the script-path hostname, remoteBase parameter, and remoteFrontendUrl parameter, which allows remote malicious users to bypass intended access restrictions via a crafted URL, a different vulnerability than CVE-2016-5143.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
google chrome |