CVE-2010-5073

Google Chrome 4 - Information Disclosure via getComputedStyle Method

Title source: llm
STIX 2.1

Description

The JavaScript implementation in Google Chrome 4 does not properly restrict the set of values contained in the object returned by the getComputedStyle method, which allows remote attackers to obtain sensitive information about visited web pages by calling this method. NOTE: this may overlap CVE-2010-5070.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13767
Exploit x_refsource_misc
http://w2spconf.com/2010/papers/p26.pdf

Scores

EPSS 0.0088
EPSS Percentile 54.9%

Details

CWE
CWE-264
Status published
Products (50)
google/chrome 4.0.212.0
google/chrome 4.0.212.1
google/chrome 4.0.221.8
google/chrome 4.0.222.0
google/chrome 4.0.222.1
google/chrome 4.0.222.5
google/chrome 4.0.222.12
google/chrome 4.0.223.0
google/chrome 4.0.223.1
google/chrome 4.0.223.2
... and 40 more
Published Dec 07, 2011
Tracked Since Feb 18, 2026