VulnerabilityModified
CVE-2011-3956
The extension implementation in Google Chrome before 17.0.963.46 does not properly handle sandboxed origins, which might allow remote attackers to bypass the Same Origin Policy via a crafted extension.
MEDIUM 6.8EPSS 0.68%
Does this matter?
Lower severity and a low EPSS score (0.68%). Track it; it rarely justifies an emergency change on its own.
Description
The extension implementation in Google Chrome before 17.0.963.46 does not properly handle sandboxed origins, which might allow remote attackers to bypass the Same Origin Policy via a crafted extension.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 0.68% probability · 50th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-346
- Affected
- google/chrome
- Source
- chrome-cve-admin@google.com
References
- http://code.google.com/p/chromium/issues/detail?id=103630
- http://googlechromereleases.blogspot.com/2012/02/stable-channel-update.html
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14906
- http://code.google.com/p/chromium/issues/detail?id=103630
- http://googlechromereleases.blogspot.com/2012/02/stable-channel-update.html
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14906
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.