Record summary

CVE-2012-4906 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.

Description

Google Chrome before 18.0.1025308 on Android does not properly restrict access to file: URLs, which allows remote attackers to obtain sensitive information via unspecified vectors, as demonstrated by obtaining credential data, a different vulnerability than CVE-2012-4903.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBGoogle Chrome for Android - Multiple 'file::' URL Handler Local Downloaded Content Disclosure VulnerabilitiesExploitDB exploitby Artem ChaykinNot analyzed1 file
ExploitDB

PoC details

References

3