Google Chrome before 4.1.249.1059 does not prevent pages from loading with the New Tab page's privileges, which has unknown impact and attack vectors.
No PoCs from references.
- https://github.com/torianne02/my-open-source-contributions