extensions/renderer/resources/platform_app.js in the Extensions subsystem in Google Chrome before 49.0.2623.75 does not properly restrict use of Web APIs, which allows remote attackers to bypass intended access restrictions via a crafted platform app.
{
"availability": "No subscription required",
"binaries": [
{
"binary_version": "49.0.2623.87-0ubuntu0.14.04.1.1112",
"binary_name": "chromium-browser"
},
{
"binary_version": "49.0.2623.87-0ubuntu0.14.04.1.1112",
"binary_name": "chromium-browser-l10n"
},
{
"binary_version": "49.0.2623.87-0ubuntu0.14.04.1.1112",
"binary_name": "chromium-chromedriver"
},
{
"binary_version": "49.0.2623.87-0ubuntu0.14.04.1.1112",
"binary_name": "chromium-codecs-ffmpeg"
},
{
"binary_version": "49.0.2623.87-0ubuntu0.14.04.1.1112",
"binary_name": "chromium-codecs-ffmpeg-extra"
}
]
}