First published: Thu Feb 18 2010(Updated: )
WebKit before r52784, as used in Google Chrome before 4.0.249.78 and Apple Safari before 4.0.5, permits cross-origin loading of CSS stylesheets even when the stylesheet download has an incorrect MIME type and the stylesheet document is malformed, which allows remote attackers to obtain sensitive information via a crafted document.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WebKit | <=r53524 | |
Google Chrome | <=4.0.249.78 | |
Safari | <=4.0.4 | |
<=r53524 | ||
<=4.0.249.78 | ||
<=4.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-0651 is classified as a medium severity vulnerability due to the potential for cross-origin attacks.
To fix CVE-2010-0651, users should update Google Chrome to version 4.0.249.78 or later and Apple Safari to version 4.0.5 or later.
CVE-2010-0651 affects Apple WebKit, Google Chrome before version 4.0.249.78, and Apple Safari before version 4.0.5.
The risks of CVE-2010-0651 include unauthorized access to sensitive information via cross-origin CSS loading.
While CVE-2010-0651 is an older vulnerability, it is essential to ensure that all affected software is updated to mitigate risk.