Security Advisory
CVE-2018-16072
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
A missing origin check related to HLS manifests in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to bypass same origin policy via a crafted HTML page.