The TreeScope::adoptIfNeeded function in WebKit/Source...
High severity
Unreviewed
Published
May 14, 2022
to the GitHub Advisory Database
•
Updated Apr 12, 2025
Description
Published by the National Vulnerability Database
May 14, 2016
Published to the GitHub Advisory Database
May 14, 2022
Last updated
Apr 12, 2025
The TreeScope::adoptIfNeeded function in WebKit/Source/core/dom/TreeScope.cpp in the DOM implementation in Blink, as used in Google Chrome before 50.0.2661.102, does not prevent script execution during node-adoption operations, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.
References