Short Name |
HTTP:STC:CHROME:GURL-XO-BYPASS1 |
---|---|
Severity |
Medium |
Recommended |
No |
Recommended Action |
Drop |
Category |
HTTP |
Keywords |
Google Chrome GURL Cross Origin Bypass1 |
Release Date |
2015/09/30 |
Update Number |
2541 |
Supported Platforms |
idp-4.0+, isg-3.1.134269+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects attemps to exploit a known Cross Origin Bypass vulnerability in Google Chrome Web browser. The vulnerability is due to insufficient validation of URLs in the Google URL (GURL) component, which can lead to violation of the same origin policy. Remote attackers can exploit this by enticing target users to visit a malicious Web site. A successful exploitation can result in information disclosure and execution of active content outside the prescribed context.