CVE-2016-5135
MEDIUMGoogle Chrome < 51.0.2704.106 - Improper Input Validation
Title source: ruleDescription
WebKit/Source/core/html/parser/HTMLPreloadScanner.cpp in Blink, as used in Google Chrome before 52.0.2743.82, does not consider referrer-policy information inside an HTML document during a preload request, which allows remote attackers to bypass the Content Security Policy (CSP) protection mechanism via a crafted web site, as demonstrated by a "Content-Security-Policy: referrer origin-when-cross-origin" header that overrides a "<META name='referrer' content='no-referrer'>" element.
Exploits (1)
github
WORKING POC
31 stars
by OpenSISE · cpoc
https://github.com/OpenSISE/CVE_PoC_Collect/tree/master/Browser/CVE-2016-5135.php
References (13)
Scores
CVSS v3
6.5
EPSS
0.0043
EPSS Percentile
62.2%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Classification
CWE
CWE-20
Status
draft
Affected Products (1)
google/chrome
< 51.0.2704.106
Timeline
Published
Jul 23, 2016
Tracked Since
Feb 18, 2026