CVE-2011-3046

Google Chrome < 17.0.963.78 - XSS

Title source: rule

Description

The extension subsystem in Google Chrome before 17.0.963.78 does not properly handle history navigation, which allows remote attackers to execute arbitrary code by leveraging a "Universal XSS (UXSS)" issue.

Scores

EPSS 0.0322
EPSS Percentile 86.9%

Classification

CWE
CWE-79
Status published

Affected Products (5)

google/chrome < 17.0.963.78
opensuse/opensuse
apple/safari < 5.1.7
apple/iphone_os < 5.1.1
n/a/n/a

Timeline

Published Mar 09, 2012
Tracked Since Feb 18, 2026