Executive brief
A security flaw in the Google Chrome web browser could allow a malicious website to access internal, privileged code. This could lead to the exposure of sensitive information or allow an attacker to bypass certain security protections within the browser. Users are protected by updating to the latest version of Chrome.
Technical details
An information exposure vulnerability (CWE-200) exists in the Google Chrome extensions API due to a leak of the 'privateClass' object. By enticing a user to visit a specially crafted HTML page, a remote attacker can exploit this leak to access privileged JavaScript code that should otherwise be restricted. This bypasses intended security boundaries between web content and the browser's internal extension framework. The vulnerability was addressed in Chrome version 54.0.2840.100 for Linux, 54.0.2840.99 for Windows, and 54.0.2840.98 for Mac.
Affected products
- Google Chrome < 54.0.2840.100 (Linux), < 54.0.2840.99 (Windows), < 54.0.2840.98 (Mac)
Timeline
- 2016-11-09: patched: Chrome Stable Channel Update released for desktop
- 2016-11-14: advisory: Red Hat security advisory RHSA-2016:2718 published
- 2017-01-19: disclosed: NVD publication date