CVE-2010-0657: Critical severity Google Chrome vulnerability
Google Chrome before 4.0.249.78 on Windows does not perform the expected encoding, escaping, and quoting for the URL in the --app argument in a desktop shortcut, which allows user-assisted remote attackers to execute arbitrary programs or obtain sensitive information by tricking a user into creating a crafted shortcut.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0657?
CVE-2010-0657 has been classified as a moderate severity vulnerability, allowing possible remote code execution.
How do I fix CVE-2010-0657?
To mitigate CVE-2010-0657, users should upgrade to Google Chrome version 4.0.249.78 or later.
What impact does CVE-2010-0657 have on users?
CVE-2010-0657 can lead to arbitrary program execution or sensitive information disclosure if a user is tricked into creating a malicious desktop shortcut.
Which versions of Google Chrome are affected by CVE-2010-0657?
CVE-2010-0657 affects Google Chrome versions before 4.0.249.78, including numerous early versions like 0.2.x and 3.0.x.
How can I check if I'm affected by CVE-2010-0657?
You can check your version of Google Chrome by going to the 'About Google Chrome' menu to see if it is below 4.0.249.78.