Bypassing Same Origin Policy in Background Fetch in Google Chrome (CVE-2021-37975)

Bypassing Same Origin Policy in Background Fetch in Google Chrome (CVE-2021-37975)

CVE-2021-38016 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Insufficient policy enforcement in background fetch in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to bypass same origin policy via a crafted HTML page.

Learn more about our Cis Benchmark Audit For Google Chrome.