CVE-2011-3887

Google Chrome <15.0.874.102 - XSS

Title source: llm
STIX 2.1

Description

Google Chrome before 15.0.874.102 does not properly handle javascript: URLs, which allows remote attackers to bypass intended access restrictions and read cookies via unspecified vectors.

Scores

EPSS 0.0052
EPSS Percentile 66.7%

Details

CWE
CWE-565
Status published
Products (3)
apple/iphone_os < 5.1
apple/safari < 5.1.4
google/chrome < 15.0.874.102
Published Oct 25, 2011
Tracked Since Feb 18, 2026