Cross-site scripting (XSS) vulnerability in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to inject arbitrary web script or HTML via vectors related to widget updates, aka "Universal XSS (UXSS)."
References
Configurations
History
No history.
Information
Published : 2016-09-11 10:59
Updated : 2024-02-04 18:53
NVD link : CVE-2016-5148
Mitre link : CVE-2016-5148
CVE.ORG link : CVE-2016-5148
JSON object : View
Products Affected
- chrome
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')