CVE-2010-4575: Input Validation
The ThemeInstalledInfoBarDelegate::Observe function in browser/extensions/themeinstalledinfobardelegate.cc in Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343 does not properly handle incorrect tab interaction by an extension, which allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted extension.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-4575?
CVE-2010-4575 has a moderate severity rating due to its potential for user-assisted remote exploitation.
How do I fix CVE-2010-4575?
To fix CVE-2010-4575, update Google Chrome to version 8.0.552.224 or later, or update Chrome OS to version 8.0.552.343 or later.
What systems are affected by CVE-2010-4575?
CVE-2010-4575 affects Google Chrome versions prior to 8.0.552.224 and Chrome OS versions prior to 8.0.552.343.
What type of attack does CVE-2010-4575 facilitate?
CVE-2010-4575 facilitates user-assisted remote attacks that exploit improper handling of tab interactions by extensions.
Was CVE-2010-4575 resolved in a security update?
Yes, CVE-2010-4575 was resolved in a security update released by Google in December 2010.