First published: Wed Dec 07 2011(Updated: )
WebKit, as used in Apple Safari 5.1.1 and earlier and Google Chrome 15 and earlier, does not prevent capture of data about the time required for image loading, which makes it easier for remote attackers to determine whether an image exists in the browser cache via crafted JavaScript code, as demonstrated by visipisi.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mobile Safari | <=5.1.1 | |
Apple WebKit | ||
Google Chrome | <=15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-4692 is classified as a high severity vulnerability due to its potential to allow remote attackers to extract information from the browser cache.
To fix CVE-2011-4692, users should update their browsers to the latest versions, specifically Safari beyond 5.1.1 and Chrome beyond version 15.
CVE-2011-4692 affects Apple Safari version 5.1.1 and earlier, Google Chrome version 15 and earlier, and Apple WebKit.
Attackers exploit CVE-2011-4692 using crafted JavaScript to determine image existence in the browser cache by measuring load times.
CVE-2011-4692 is considered widespread as it affects multiple versions of popular web browsers, making it relevant for many users.