CVE-2012-4907: Critical severity google chrome (trace event) vulnerability
Google Chrome before 18.0.1025308 on Android does not properly restrict access from JavaScript code to Android APIs, which allows remote attackers to have an unspecified impact via a crafted web page.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Users of Google Chrome on Android are exposed if they use a version earlier than 18.0.1025308 and visit a malicious web page.
What does an attacker need to exploit it?
An attacker needs to induce the user to load a crafted web page. The vulnerability is remotely exploitable and does not require authentication.
Is a default browser configuration affected?
The available data identifies affected Chrome for Android versions but does not describe any configuration prerequisite, so no special configuration requirement is documented.
How can I determine whether I am affected?
Check the installed Google Chrome version on Android. Versions before 18.0.1025308 are affected.
What should be done if patching is not immediately possible?
Avoid visiting untrusted or attacker-supplied web pages until Chrome can be updated to version 18.0.1025308 or later.