CVE-2011-3046: XSS
Published Mar 9, 2012
·Updated
The extension subsystem in Google Chrome before 17.0.963.78 does not properly handle history navigation, which allows remote attackers to execute arbitrary code by leveraging a "Universal XSS (UXSS)" issue.
Affected Software
4 affected components
Google Chrome<17.0.963.78
openSUSE openSUSE=12.1
Apple iPhone OS<5.1.1
Apple Safari<5.1.7
Event History
Mar 9, 2012
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-3046?
CVE-2011-3046 has a high severity rating due to the potential for remote code execution.
2
How do I fix CVE-2011-3046?
To fix CVE-2011-3046, update Google Chrome to version 17.0.963.78 or later.
3
What types of attacks can exploit CVE-2011-3046?
CVE-2011-3046 can be exploited through Universal XSS (UXSS) attacks.
4
What versions of Google Chrome are affected by CVE-2011-3046?
CVE-2011-3046 affects Google Chrome versions prior to 17.0.963.78.
5
Are other browsers affected by CVE-2011-3046?
Yes, other browsers including versions of Apple Safari and openSUSE are also affected by CVE-2011-3046.