Junglewise Threat Intelligence

CVE-2016-9650: Google Chrome Blink no-referrer policy bypass in iframes

CVE-2016-9650 · Severity: medium · CVSS 4.3 · Published 2017-01-19

Technologies: Google Chrome, Google Chromium. Vendors: Google.

Executive brief

A vulnerability in the Google Chrome web browser could allow a malicious website to bypass privacy settings intended to hide where a user is visiting from. Specifically, it allows a site to see the 'referrer' information even when a 'no-referrer' policy is in place. This could lead to the unintended disclosure of sensitive URL information to third-party websites.

Technical details

A vulnerability exists in the Blink rendering engine within Google Chrome due to improper handling of iframes. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page, which allows the attacker to bypass the Content Security Policy (CSP) 'no-referrer' directive. This results in the disclosure of referrer information that should have been suppressed. The issue affects Chrome on Mac, Windows, Linux, and Android, and was addressed in version 55.0.2883.75 for desktop and 55.0.2883.84 for Android.

Affected products

  • Google Chrome prior to 55.0.2883.75 (Desktop); prior to 55.0.2883.84 (Android)
  • Google Chromium prior to 55.0.2883.75

Timeline

  • 2016-12-01: patched: Chrome 55.0.2883.75 released for desktop
  • 2017-01-19: disclosed: NVD publication date

References

Related threats