Inappropriate implementation in File Picker in Google Chrome prior to 139.0.7258.127 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
The requirements for the product dictate the use of an established authentication algorithm, but the implementation of the algorithm is incorrect.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Chrome | * | 139.0.7258.127 (excluding) | |
Chromium-browser | Ubuntu | upstream | * |