High
CVSS 8.8
Overview
Failure to disallow PWA installation from CSP sandboxed pages in AppManifest in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to access privileged APIs via a crafted HTML page.
Failure to disallow PWA installation from CSP sandboxed pages in AppManifest in ...
Failure to disallow PWA installation from CSP sandboxed pages in AppManifest in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to access privileged APIs via a crafted HTML page.
This vulnerability is rated 🟠 HIGH.
Recommended actions: