Google Chrome
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*, +1 more
- < 148.0.7778.96
A vulnerability in Google Chrome's handling of Cross-Origin Resource Sharing (CORS) prior to version 148.0.7778.96 allowed remote attackers to bypass the same-origin policy. This was achieved through insufficient validation of untrusted input, enabling the execution of malicious actions via a crafted HTML page. The vulnerability affected the renderer process, where the exploitation occurred.
Exploitation of this vulnerability allowed for a same-origin policy bypass, which could lead to unauthorized access or manipulation of resources between different origins.
Users can update to Google Chrome version 148.0.7778.96 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.