CVE-2017-15419
28.08.2018, 19:29
Insufficient policy enforcement in Resource Timing API in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to infer browsing history by triggering a leaked cross-origin URL via a crafted HTML page.
Vendor | Product | Version |
---|---|---|
redhat | enterprise_linux_desktop | 6.0 |
redhat | enterprise_linux_server | 6.0 |
redhat | enterprise_linux_workstation | 6.0 |
debian | debian_linux | 9.0 |
chrome | 𝑥 < 63.0.3239.84 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
chromium-browser |
| ||||||||||||
oxide-qt |
|
Common Weakness Enumeration
References