CVE-2010-0646: Critical severity Google Chrome vulnerability
Multiple integer signedness errors in factory.cc in Google V8 before r3560, as used in Google Chrome before 4.0.249.89, allow remote attackers to execute arbitrary code in the Chrome sandbox via crafted use of JavaScript arrays.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0646?
CVE-2010-0646 is classified as a critical vulnerability that allows remote attackers to execute arbitrary code in the Chrome sandbox.
How do I fix CVE-2010-0646?
To fix CVE-2010-0646, update Google Chrome to version 4.0.249.89 or later.
What versions of Google Chrome are affected by CVE-2010-0646?
CVE-2010-0646 affects multiple versions of Google Chrome prior to 4.0.249.89, including versions as low as 0.2.149.27.
Who can be attacked using CVE-2010-0646?
Remote attackers can exploit CVE-2010-0646 to compromise users of vulnerable versions of Google Chrome.
What type of vulnerability is CVE-2010-0646?
CVE-2010-0646 is characterized as an integer signedness error that affects the JavaScript engine in Google Chrome.