Executive brief
A vulnerability in Google Chrome's web engine allowed websites to bypass security restrictions known as Content Security Policy (CSP). CSP is a security layer that helps detect and mitigate certain types of attacks, including data theft and site defacement. By exploiting this flaw through a specially crafted web page, an attacker could bypass these protections, potentially leading to unauthorized actions on behalf of the user.
Technical details
A vulnerability exists in the Blink rendering engine of Google Chrome due to improper handling of form actions. This flaw allows a remote attacker to bypass Content Security Policy (CSP) protections by enticing a user to visit a specially crafted HTML page. The root cause is a data processing error (CWE-19) in how form-related actions are validated against CSP directives. Successful exploitation allows an attacker to circumvent security restrictions that would otherwise prevent unauthorized script execution or data exfiltration. The issue was addressed in Chrome version 55.0.2883.75 for desktop and 55.0.2883.84 for Android.
Affected products
- Google Chrome prior to 55.0.2883.75
- Google Chrome prior to 55.0.2883.84 (Android)
- Google Chromium prior to 55.0.2883.75
Timeline
- 2016-12-01: patched: Chrome 55.0.2883.75 released for desktop
- 2016-12-05: advisory: Gentoo GLSA 201612-11 published
- 2016-12-07: advisory: Red Hat RHSA-2016:2919 published
- 2017-01-19: disclosed: NVD publication date