Executive brief
A vulnerability in Google Chrome's web rendering engine could allow a malicious website to bypass security boundaries that normally prevent sites from interacting with each other. By using a specialized timing attack related to how the browser processes graphics (SVG filters), an attacker could potentially access or manipulate data from other open websites. This could lead to unauthorized access to user sessions or sensitive information if a victim visits a specially crafted web page.
Technical details
A side-channel timing attack exists in the Blink rendering engine's implementation of SVG filters. The vulnerability stems from the way denormalized floating point arithmetic is handled during graphics processing, which exhibits measurable timing differences. A remote attacker can exploit this by enticing a user to visit a malicious HTML page containing crafted SVG content. By measuring the time taken to process these filters, the attacker can bypass the Same Origin Policy (SOP) to infer information about content from different origins. The issue was addressed in Google Chrome version 55.0.2883.75 for desktop and 55.0.2883.84 for Android.
Affected products
- Google Chrome Prior to 55.0.2883.75 (Desktop); Prior to 55.0.2883.84 (Android)
- Google Chromium Prior to 55.0.2883.75
Timeline
- 2016-12-01: advisory: Google Chrome stable channel update released
- 2016-12-05: advisory: Gentoo Linux security advisory published
- 2016-12-07: patched: Red Hat Enterprise Linux security update released
- 2017-01-19: disclosed: NVD publication date