Tavis Ormandy, a security expert at Google Project Zero, has discovered a critical remote code execution vulnerability in the Cisco WebEx browser extension. The flaw has a significant impact considering that the WebEx extension for Google Chrome has roughly 20 million active users. Ciscos initial fix does not appear to be complete, which has led to Google and Mozilla temporarily removing the add-on from their stores. The expert discovered that an attacker can trigger the vulnerability by using any URL that contains a magic pattern.”]
Source: http://securityaffairs.co/wordpress/55618/hacking/cisco-webex-rce-flaw.html

