The autosuggest feature in the Omnibox implementation in Google Chrome before 5.0.375.127 does not anticipate entry of passwords, which might allow remote attackers to obtain sensitive information by reading the network traffic generated by this feature.
References
Link | Resource |
---|---|
http://code.google.com/p/chromium/issues/detail?id=51146 | Exploit Issue Tracking Patch Vendor Advisory |
http://googlechromereleases.blogspot.com/2010/08/stable-channel-update_19.html | Vendor Advisory |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11839 | Third Party Advisory |
Configurations
Information
Published : 2010-08-24 13:00
Updated : 2020-08-04 09:44
NVD link : CVE-2010-3118
Mitre link : CVE-2010-3118
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
- chrome