CVE-2016-5132 describes a Same Origin Policy bypass vulnerability in Google Chrome versions prior to 52.0.2743.82. The Service Workers subsystem incorrectly handled Secure Contexts, allowing remote attackers to bypass security restrictions by embedding an HTTPS IFRAME within an HTTP IFRAME. This vulnerability carries a high CVSS score of 8.8, indicating a network-based attack with low complexity that could lead to high confidentiality, integrity, and availability impacts if a user interacts with a malicious page. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability received moderate community attention and media coverage at the time of its disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 51.0.2704.106CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.