CVE-2010-0661

WebKit - Same Origin Policy Bypass via window.open Method

Title source: llm
STIX 2.1

Description

WebCore/bindings/v8/custom/V8DOMWindowCustom.cpp in WebKit before r52401, as used in Google Chrome before 4.0.249.78, allows remote attackers to bypass the Same Origin Policy via vectors involving the window.open method.

References (11)

Core 11
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/43068
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0212
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1023506
Various Sources x_refsource_confirm
http://flock.com/security/
Various Sources x_refsource_confirm
https://bugs.webkit.org/show_bug.cgi?id=32647
Patch x_refsource_confirm
http://trac.webkit.org/changeset/52401
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14482

Scores

EPSS 0.0159
EPSS Percentile 73.2%

Details

CWE
CWE-264
Status published
Products (49)
apple/webkit 52400
google/chrome 0.2.149.27
google/chrome 0.2.149.29
google/chrome 0.2.149.30
google/chrome 0.2.152.1
google/chrome 0.2.153.1
google/chrome 0.3.154.0
google/chrome 0.3.154.3
google/chrome 0.4.154.18
google/chrome 0.4.154.22
... and 39 more
Published Feb 18, 2010
Tracked Since Feb 18, 2026