First published: Wed Jan 09 2019(Updated: )
Using an ID that can be controlled by a compromised renderer which allows any frame to overwrite the page_state of any other frame in the same process in Navigation in Google Chrome on Chrome OS prior to 62.0.3202.74 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome | <62.0.3202.74 | |
Chrome OS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-15402 has a medium severity rating, indicating a moderate risk to affected systems.
To fix CVE-2017-15402, update Google Chrome to version 62.0.3202.74 or later.
CVE-2017-15402 affects Google Chrome versions before 62.0.3202.74.
Yes, CVE-2017-15402 can allow a remote attacker to execute code through a compromised renderer.
CVE-2017-15402 is applicable to Google Chrome on Chrome OS prior to version 62.0.3202.74.