Universal cross-site scripting in Google Chrome - CVE-2017-15429
Published: December 15, 2017 / Updated: June 11, 2021
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists in V8 due to insufficient sanitization of user-supplied data. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Affected software
Arch Linux
Gentoo Linux
Debian Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Workstation
Fedora
Opensuse
qt5-qtwebengine
chromium
How to mitigate CVE-2017-15429
qt5-qtwebengine - addressed in versions 5.10.1-4.fc26, 5.10.1-4.fc27, 5.10.1-4.fc28
chromium - addressed in versions 63.0.3239.108-1.fc26, 63.0.3239.108-1.fc27
External References
Related Security Bulletins
- Cross-site scripting in Google Chrome
- Arch Linux update for chromium
- Red Hat update for Google Chrome
- openSUSE update for chromium
- Gentoo update for Chromium, Google Chrome
- Debian update for chromium-browser
- OpenSUSE Linux update for chromium
- Fedora 27 update for chromium
- Fedora 26 update for chromium
- Fedora 26 update for qt5-qtwebengine
- Fedora 28 update for qt5-qtwebengine
- Fedora 27 update for qt5-qtwebengine