Insufficient validation of untrusted input in Downloads in Google Chrome on Windows prior to 1.74 allowed a remote attacker to bypass download restrictions via a crafted HTML page. Inappropriate implementation in in File System API in Google Chrome on Windows prior to 1.74 allowed a remote attacker to bypass file system restrictions via a crafted HTML page. Insufficient policy enforcement in CORS in Google Chrome prior to 1.74 allowed a remote attacker to leak cross-origin data via a crafted HTML page. Use after free in WebTransport in Google Chrome prior to 1.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Use after free in WebRTC in Google Chrome prior to 1.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Type Confusion in ServiceWorker API in Google Chrome prior to 1.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Use after free in GuestView in Google Chrome prior to 1.119 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a Chrome web app. Type confusion in V8 in Google Chrome prior to 1.77 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Inappropriate implementation in Full screen mode in Google Chrome on Android prior to 1.77 allowed a remote attacker to spoof the contents of the security UI via a crafted HTML page. Out of bounds read in WebRTC in Google Chrome prior to 1.77 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. Use after free in GPU in Google Chrome prior to 1.77 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page and browser shutdown. Inappropriate implementation in Download in Google Chrome prior to 1.77 allowed a remote attacker to potentially spoof the contents of the Omnibox (URL bar) via a crafted HTML page. ![]() Heap buffer overflow in WebUI in Google Chrome prior to 1.77 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via UI interaction. Type confusion in Data Transfer in Google Chrome prior to 1.77 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page. ![]() Type confusion in DevTools in Google Chrome prior to 1.77 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via UI interactions. Insufficient policy enforcement in DevTools in Google Chrome prior to 1.77 allowed a remote attacker to bypass same origin policy and proxy settings via a crafted HTML page. Integer overflow in Core in Google Chrome prior to 1.77 allowed a remote attacker who had one a race condition to potentially exploit heap corruption via a crafted HTML page.
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |