Cross-domain vulnerability in the V8 JavaScript engine in Google Chrome before 1.0.154.46 allows remote attackers to bypass the Same Origin Policy via a crafted script that accesses another frame and reads its full URL and possibly other sensitive information, or modifies the URL of this frame.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2009-02-03 11:30
Updated : 2009-02-03 21:00
NVD link : CVE-2009-0276
Mitre link : CVE-2009-0276
JSON object : View
CWE
Products Affected
- chrome