CVE-2017-15402

CVE-2017-15402

Using an ID that can be controlled by a compromised renderer which allows any frame to overwrite the page_state of any other frame in the same process in Navigation in Google Chrome on Chrome OS prior to 62.0.3202.74 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

Source: CVE-2017-15402

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다