The Extensions subsystem in Google Chrome before 48.0.2564.109 does not prevent use of the Object.defineProperty method to override intended extension behavior, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code.
                
            Metrics
Affected Vendors & Products
References
        History
                    No history.
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: Chrome
Published: 2016-02-14T02:00:00
Updated: 2024-08-05T23:02:12.345Z
Reserved: 2016-01-12T00:00:00
Link: CVE-2016-1622
 Vulnrichment
                        Vulnrichment
                    No data.
 NVD
                        NVD
                    Status : Deferred
Published: 2016-02-14T02:59:00.117
Modified: 2025-04-12T10:46:40.837
Link: CVE-2016-1622
 Redhat
                        Redhat