CVE-2010-0556: Medium severity Google Chrome vulnerability
browser/login/loginprompt.cc in Google Chrome before 4.0.249.89 populates an authentication dialog with credentials that were stored by Password Manager for a different web site, which allows user-assisted remote HTTP servers to obtain sensitive information via a URL that requires authentication, as demonstrated by a URL in the SRC attribute of an IMG element.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0556?
CVE-2010-0556 is classified as a medium severity vulnerability.
How do I fix CVE-2010-0556?
To mitigate CVE-2010-0556, users should update Google Chrome to version 4.0.249.89 or later.
What causes CVE-2010-0556?
CVE-2010-0556 occurs when the Google Chrome browser incorrectly populates authentication dialogs with credentials from the Password Manager for different websites.
Which versions of Google Chrome are affected by CVE-2010-0556?
CVE-2010-0556 affects all versions of Google Chrome prior to 4.0.249.89.
Can CVE-2010-0556 lead to credential theft?
Yes, CVE-2010-0556 can potentially lead to credential theft if a user interacts with a malicious URL requiring authentication.