Executive brief
A vulnerability in the Google Chrome PDF viewer allowed malicious websites to bypass security restrictions that normally prevent one site from accessing data from another. By tricking a user into visiting a specially crafted web page, an attacker could potentially steal sensitive information or perform unauthorized actions on other websites the user is logged into. This issue affected Chrome on Windows, Mac, Linux, and Android.
Technical details
A Same-Origin Policy (SOP) bypass vulnerability existed in the PDFium component of Google Chrome. The root cause was the PDF plugin's incorrect handling of HTTP redirects, which could be leveraged to bypass origin-based security boundaries. A remote attacker could exploit this by hosting a malicious HTML page that, when visited by a user, uses the PDF plugin to access data across origins. This could lead to the disclosure of sensitive information or unauthorized state-changing requests. The issue was resolved in Chrome version 55.0.2883.75 for desktop and 55.0.2883.84 for Android.
Affected products
- Google Chrome Prior to 55.0.2883.75 (Desktop); Prior to 55.0.2883.84 (Android)
- Google Chromium Prior to 55.0.2883.75
Timeline
- 2016-12-01: advisory: Google Chrome stable channel update released
- 2016-12-05: advisory: Gentoo Linux security advisory published
- 2016-12-07: patched: Red Hat Enterprise Linux security update released
- 2017-01-19: disclosed: NVD publication date