← Back to CVE List
Vulnerability Intelligence Report

CVE-2016-5128

objects.cc in Google V8 before 5.2.361.27, as used in Google Chrome before 52.0.2743.82, does not prevent API interceptors from modifying a store target without setting a property, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.

No Active Exploit Signals
CVSS Base Score
8.8
HIGH
EPSS Probability:1.27%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Affected Products & Versions

Vendor Product Affected Versions
google chrome all
google v8 5.2.360

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
1.268%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityChrome · Vendor · USA
Reserved2016-05-31T00:00:00
Published2016-07-23T19:00:00
Patch Date2016-07-20
Last Updated2024-08-06T00:53:47

LINK COPIED TO CLIPBOARD