Google Chrome contains a flaw as the tabs permission for extensions allows capturing images of local file via the 'captureVisibleTab' method. With a specially crafted Chrome extension (CRX) file, a context-dependent attacker can capture images of any "file://" resource.
Classification
Location:
Context Dependent
Attack Type:
Information Disclosure
Impact:
Loss of Confidentiality
Solution:
Upgrade
Exploit:
Exploit Public
Disclosure:
Vendor Verified,
Coordinated Disclosure
Solution
Upgrade to version 11.0.696.57 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.