Google Chrome before 9.0.597.107 does not properly restrict access to internal extension functions, which has unspecified impact and remote attack vectors.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Link | Tags |
---|---|
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13978 | vdb entry third party advisory signature |
http://code.google.com/p/chromium/issues/detail?id=72214 | issue tracking patch vendor advisory exploit |
http://www.securityfocus.com/bid/46614 | vdb entry third party advisory |
http://googlechromereleases.blogspot.com/2011/02/stable-channel-update_28.html | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/65741 | vdb entry third party advisory |