The autosuggest feature in the Omnibox implementation in Google Chrome before 5.0.375.127 does not anticipate entry of passwords, which might allow remote attackers to obtain sensitive information by reading the network traffic generated by this feature.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://googlechromereleases.blogspot.com/2010/08/stable-channel-update_19.html | vendor advisory |
http://code.google.com/p/chromium/issues/detail?id=51146 | issue tracking patch vendor advisory exploit |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11839 | vdb entry third party advisory signature |