CVE-2017-15402: Input Validation
Using an ID that can be controlled by a compromised renderer which allows any frame to overwrite the pagestate of any other frame in the same process in Navigation in Google Chrome on Chrome OS prior to 62.0.3202.74 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-15402?
CVE-2017-15402 has a medium severity rating, indicating a moderate risk to affected systems.
How do I fix CVE-2017-15402?
To fix CVE-2017-15402, update Google Chrome to version 62.0.3202.74 or later.
What versions of Google Chrome are affected by CVE-2017-15402?
CVE-2017-15402 affects Google Chrome versions before 62.0.3202.74.
Can CVE-2017-15402 lead to remote code execution?
Yes, CVE-2017-15402 can allow a remote attacker to execute code through a compromised renderer.
On which platforms is CVE-2017-15402 applicable?
CVE-2017-15402 is applicable to Google Chrome on Chrome OS prior to version 62.0.3202.74.