CVE-2011-3056Origin Validation Error in Google Chrome

Severity
6.8MEDIUMNVD
EPSS
0.9%
top 24.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 22
Latest updateMay 13

Description

Google Chrome before 17.0.963.83 allows remote attackers to bypass the Same Origin Policy via vectors involving a "magic iframe."

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages4 packages

NVDgoogle/chrome< 17.0.963.83
NVDapple/safari< 5.1.7
NVDapple/iphone_os< 5.1.1

🔴Vulnerability Details

1
GHSA
GHSA-rjjp-92fx-h9v7: Google Chrome before 172022-05-13

📋Vendor Advisories

1
Red Hat
Webkitgtk: google chrome update [21-March-2012]2012-03-21

💬Community

1
Bugzilla
Webkitgtk: google chrome update [21-March-2012]2012-03-27