CVE-2009-1412
Argument injection vulnerability in the chromehtml: protocol handler in Google Chrome before 1.0.154.59, when invoked by Internet Explorer, allows remote attackers to determine the existence of files, and open tabs for URLs that do not satisfy the…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.21%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Argument injection vulnerability in the chromehtml: protocol handler in Google Chrome before 1.0.154.59, when invoked by Internet Explorer, allows remote attackers to determine the existence of files, and open tabs for URLs that do not satisfy the IsWebSafeScheme restriction, via a web page that sets document.location to a chromehtml: value, as demonstrated by use of a (1) javascript: or (2) data: URL. NOTE: this can be leveraged for Universal XSS by exploiting certain behavior involving persistence across page transitions.
- CVSS 2.0
- 7.8 HIGHAV:N/AC:L/Au:N/C:C/I:N/A:N
- EPSS
- 1.21% probability · 67th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- google/chrome
- Source
- cve@mitre.org
References
- http://chromium.googlecode.com/issues/attachment?aid=5579180911289877192&name=Google+Chrome+Advisory.docExploit, Vendor Advisory
- http://code.google.com/p/chromium/issues/detail?id=9860Exploit
- http://googlechromereleases.blogspot.com/2009/04/stable-update-security-fix.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50449
- http://chromium.googlecode.com/issues/attachment?aid=5579180911289877192&name=Google+Chrome+Advisory.docExploit, Vendor Advisory
- http://code.google.com/p/chromium/issues/detail?id=9860Exploit
- http://googlechromereleases.blogspot.com/2009/04/stable-update-security-fix.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50449
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.