cbcvebase.
CVE-2010-0657
published 2010-02-18

CVE-2010-0657: Google Chrome before 4.0.249.78 on Windows does not perform the expected encoding, escaping, and quoting for the URL in the --app argument in a desktop…

PriorityP337critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
1.88%
77.5th percentile
Google Chrome before 4.0.249.78 on Windows does not perform the expected encoding, escaping, and quoting for the URL in the --app argument in a desktop shortcut, which allows user-assisted remote attackers to execute arbitrary programs or obtain sensitive information by tricking a user into creating a crafted shortcut.

Affected

46 ranges· showing 25
VendorProductVersion rangeFixed in
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.