The sandbox implementation in Google Chrome before 6.0.472.53 does not properly deserialize parameters, which has unspecified impact and remote attack vectors.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Link | Tags |
---|---|
http://code.google.com/p/chromium/issues/detail?id=52682 | issue tracking patch vendor advisory exploit |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12133 | vdb entry third party advisory signature |
http://googlechromereleases.blogspot.com/2010/09/stable-and-beta-channel-updates.html | vendor advisory |