VYPR
High severity8.8NVD Advisory· Published Jun 5, 2016· Updated Jun 17, 2026

CVE-2016-1697

CVE-2016-1697

Description

The FrameLoader::startLoad function in WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 51.0.2704.79, does not prevent frame navigations during DocumentLoader detach operations, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

13

Patches

Vulnerability mechanics

References

10

News mentions

0

No linked articles in our index yet.