CVE-2010-0661: Medium severity Apple WebKit vulnerability
WebCore/bindings/v8/custom/V8DOMWindowCustom.cpp in WebKit before r52401, as used in Google Chrome before 4.0.249.78, allows remote attackers to bypass the Same Origin Policy via vectors involving the window.open method.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0661?
CVE-2010-0661 is considered to be of high severity as it allows remote attackers to bypass the Same Origin Policy.
How do I fix CVE-2010-0661?
To fix CVE-2010-0661, update WebKit to version r52401 or later, or upgrade Google Chrome to version 4.0.249.78 or higher.
What versions are affected by CVE-2010-0661?
CVE-2010-0661 affects several versions of WebKit and Google Chrome prior to their respective patched versions.
What attack vectors does CVE-2010-0661 involve?
CVE-2010-0661 involves attack vectors that exploit the window.open method to bypass security restrictions.
Is CVE-2010-0661 still a concern today?
CVE-2010-0661 is generally not a concern today as it applies to outdated software that has since been updated to mitigate the vulnerability.