The Web Workers implementation in Google Chrome before 10.0.648.127 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, related to an "error message leak."
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://code.google.com/p/chromium/issues/detail?id=70336 | patch exploit vendor advisory issue tracking |
http://www.securityfocus.com/bid/46785 | third party advisory vdb entry |
http://lists.apple.com/archives/Security-announce/2011//Oct/msg00001.html | vendor advisory mailing list third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/65954 | third party advisory vdb entry |
http://googlechromereleases.blogspot.com/2011/03/chrome-stable-release.html | vendor advisory |
http://support.apple.com/kb/HT4999 | third party advisory |
http://support.apple.com/kb/HT4808 | third party advisory |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14398 | signature third party advisory vdb entry |
http://lists.apple.com/archives/security-announce/2011//Jul/msg00002.html | vendor advisory mailing list third party advisory |
http://www.vupen.com/english/advisories/2011/0628 | vdb entry permissions required |