Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Google Chrome Cross Site Scripting and Cross Domain Security Bypass Vulnerabilities

Google Chrome is prone to multiple cross-site scripting vulnerabilities and a cross-domain security-bypass vulnerability.

An attacker may leverage the cross-site scripting issues to execute arbitrary script code in the browser of an unsuspecting user in the context of an arbitrary site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.

The cross-domain security-bypass vulnerability will allow the attacker to bypass the same-origin policy and obtain potentially sensitive information.

These issues affect versions prior to Google Chrome 1.0.154.46.







 

Privacy Statement
Copyright 2008, SecurityFocus