The sandbox implementation in Google Chrome before 9.0.597.84 on Mac OS X might allow remote attackers to obtain potentially sensitive information about local files via vectors related to the stat system call.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13895 | vdb entry third party advisory signature |
http://code.google.com/p/chromium/issues/detail?id=42989 | issue tracking patch vendor advisory exploit |
http://googlechromereleases.blogspot.com/2011/02/stable-channel-update.html | vendor advisory |