SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2011-3055

The browser native UI in Google Chrome before 17.0.963.83 does not require user confirmation before an unpacked extension installation, which allows user-assisted remote attackers to have an unspecified impact via a crafted extension.

MEDIUM 4.3EPSS 1.69%

Does this matter?

Lower severity and a low EPSS score (1.69%). Track it; it rarely justifies an emergency change on its own.

Description

The browser native UI in Google Chrome before 17.0.963.83 does not require user confirmation before an unpacked extension installation, which allows user-assisted remote attackers to have an unspecified impact via a crafted extension.

CVSS 2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
1.69% probability · 76th percentile
CISA KEV
Not listed
Weakness
CWE-306
Affected
google/chrome · opensuse/opensuse
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.