CVE-2016-5173

Source
https://cve.org/CVERecord?id=CVE-2016-5173
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-5173.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2016-5173
Downstream
Related
Withdrawn
2026-05-04T08:14:01.675009Z
Published
2016-09-25T20:59:05.807Z
Modified
2026-05-04T08:14:01.675009Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L CVSS Calculator
Summary
[none]
Details

The extensions subsystem in Google Chrome before 53.0.2785.113 does not properly restrict access to Object.prototype, which allows remote attackers to load unintended resources, and consequently trigger unintended JavaScript function calls and bypass the Same Origin Policy via an indirect interception attack.

References

Affected packages

Git /

Affected ranges

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "53.0.2785.101"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-5173.json"