CVE-2010-3258: Critical severity google chrome (trace event) vulnerability
Published Sep 7, 2010
·Updated
The sandbox implementation in Google Chrome before 6.0.472.53 does not properly deserialize parameters, which has unspecified impact and remote attack vectors.
Affected Software
1 affected component
Google Chrome<6.0.472.53
Remediation
Patch Available
Event History
Sep 7, 2010
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
Which Chrome versions are affected?
Google Chrome versions before 6.0.472.53 are affected.
2
Can this be exploited remotely without authentication?
Yes. The CVSS vector identifies network access and no authentication requirement, with medium attack complexity.
3
What is the potential security impact?
The issue is rated critical with a 9.3 severity score and may affect confidentiality, integrity, and availability.
4
What should organizations do?
Apply the available patch by updating Chrome to version 6.0.472.53 or later.