Inappropriate implementation in Extensions in Google Chrome prior to 131.0.6778.69 allowed a remote attacker to bypass site isolation via a crafted Chrome Extension. (Chromium security severity: High)
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://chromereleases.googleblog.com/2024/11/stable-channel-update-for-desktop_12.html | release notes |
https://issues.chromium.org/issues/373263969 | permissions required |