Insufficient policy enforcement in WebSockets in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass same origin policy via a crafted HTML page.
The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Chrome | * | 79.0.3945.79 (excluding) | |
| Red Hat Enterprise Linux 6 Supplementary | RedHat | chromium-browser-0:79.0.3945.79-1.el6_10 | * |
| Chromium-browser | Ubuntu | bionic | * |
| Chromium-browser | Ubuntu | devel | * |
| Chromium-browser | Ubuntu | disco | * |
| Chromium-browser | Ubuntu | eoan | * |
| Chromium-browser | Ubuntu | trusty | * |
| Chromium-browser | Ubuntu | upstream | * |
| Chromium-browser | Ubuntu | xenial | * |