CVE-2016-2845

MEDIUM

Google Chrome < 48.0.2564.116 - Information Disclosure

Title source: rule

Description

The Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 49.0.2623.75, does not ignore a URL's path component in the case of a ServiceWorker fetch, which allows remote attackers to obtain sensitive information about visited web pages by reading CSP violation reports, related to FrameFetchContext.cpp and ResourceFetcher.cpp.

Scores

CVSS v3 5.3
EPSS 0.0065
EPSS Percentile 70.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Classification

CWE
CWE-200
Status draft

Affected Products (1)

google/chrome < 48.0.2564.116

Timeline

Published Mar 06, 2016
Tracked Since Feb 18, 2026