First published: Thu Feb 18 2010(Updated: )
WebKit before r52784, as used in Google Chrome before 4.0.249.78 and Apple Safari before 4.0.5, permits cross-origin loading of CSS stylesheets even when the stylesheet download has an incorrect MIME type and the stylesheet document is malformed, which allows remote attackers to obtain sensitive information via a crafted document.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Webkit | <=r53524 | |
Google Chrome | <=4.0.249.78 | |
Apple Safari | <=4.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.