Inappropriate implementation in Internals in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to spoof the origin of an iframe via a crafted HTML page. (Chromium security severity: Low)
No PoCs from references.
- https://github.com/ARPSyndicate/cvemon
- https://github.com/dhalubiec/baw-project