Executive brief
A security flaw in Google Chrome's extensions and PDF viewing components could allow a malicious website to bypass security boundaries. By tricking a user into visiting a specially crafted web page, an attacker could gain unauthorized access to internal browser functions. This could lead to a compromise of the browser's site isolation protections, which are designed to keep data from different websites separate.
Technical details
An improper access control vulnerability exists in the extensions API and PDFium component of Google Chrome. The flaw stems from the use of unvalidated data which incorrectly permitted access to privileged plugins. A remote attacker can exploit this by hosting a crafted HTML page; if a user visits this page, the attacker can bypass site isolation mechanisms. This bypass could allow the attacker to interact with browser components or data that should be restricted to a higher privilege level. The issue was addressed in Chrome version 55.0.2883.75 for desktop and 55.0.2883.84 for Android.
Affected products
- Google Chrome < 55.0.2883.75 (Desktop); < 55.0.2883.84 (Android)
- Google Chromium < 55.0.2883.75
Timeline
- 2016-12-01: patched: Chrome 55.0.2883.75 released for desktop
- 2016-12-05: advisory: Gentoo GLSA 201612-11 published
- 2016-12-07: advisory: Red Hat RHSA-2016:2919 published
- 2017-01-19: disclosed: NVD publication date