Home 148.0.7778.96 (custom) before 148.0.7778.96
affected
Description
Insufficient validation of untrusted input in CORS in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
Problem types
Insufficient validation of untrusted input
Product status
References
chromereleases.googleblog.com/...nel-update-for-desktop.html
issues.chromium.org/issues/497432281