Executive brief
A security vulnerability in Google Chrome for Android could allow a malicious website to access a user's downloaded files and interact with other websites they are logged into. This occurs because the browser failed to properly isolate downloaded files from other web content. An attacker could use this to steal sensitive personal data or perform unauthorized actions on a user's online accounts if the user visits a specially crafted webpage.
Technical details
A vulnerability in the content renderer client of Google Chrome for Android prior to version 54.0.2840.85 resulted from insufficient enforcement of the Same Origin Policy (SOP) regarding downloaded files. By inducing a user to visit a malicious HTML page, a remote attacker could bypass origin restrictions to read any file previously downloaded to the device. Furthermore, the flaw allowed the attacker to interact with other web origins, potentially hijacking active sessions where the user was already authenticated. The issue was addressed in the 54.0.2840.85 update for Android.
Affected products
- Google Chrome Prior to 54.0.2840.85
Timeline
- 2016-10-31: patched: Chrome for Android updated to 54.0.2840.85 to address the issue.
- 2017-01-19: disclosed: Public disclosure of CVE-2016-5196.