The Service Workers subsystem in Google Chrome before 52.0.2743.82 does not properly implement the Secure Contexts specification during decisions about whether to control a subframe, which allows remote attackers to bypass the Same Origin Policy via an https IFRAME element inside an http IFRAME element.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2024-08-06T00:53:47.986Z

Reserved: 2016-05-31T00:00:00

Link: CVE-2016-5132

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2016-07-23T19:59:14.860

Modified: 2025-04-12T10:46:40.837

Link: CVE-2016-5132

cve-icon Redhat

Severity : Moderate

Publid Date: 2016-07-20T00:00:00Z

Links: CVE-2016-5132 - Bugzilla

cve-icon OpenCVE Enrichment

No data.