CVE-2016-1682: Medium severity google chrome vulnerability
The following flaw was identified in the Chromium browser: csp bypass for serviceworker.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=579801
External References:
http://googlechromereleases.blogspot.com/2016/05/stable-channel-update25.html
Other sources
The ServiceWorkerContainer::registerServiceWorkerImpl function in WebKit/Source/modules/serviceworkers/ServiceWorkerContainer.cpp in Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Content Security Policy (CSP) protection mechanism via a ServiceWorker registration.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1682?
CVE-2016-1682 has a medium severity rating as it allows remote attackers to bypass Content Security Policy protection mechanisms.
How do I fix CVE-2016-1682?
To fix CVE-2016-1682, update Google Chrome to version 51.0.2704.63 or later.
Which versions of Google Chrome are affected by CVE-2016-1682?
Google Chrome versions up to and including 50.0.2661.102 are affected by CVE-2016-1682.
What impact does CVE-2016-1682 have on web security?
CVE-2016-1682 can potentially allow malicious scripts to execute, compromising the integrity of user data due to the bypass of Content Security Policies.
Is CVE-2016-1682 related to specific operating systems?
CVE-2016-1682 affects Google Chrome running on various operating systems, including Linux distributions like Ubuntu and Debian.