WebKit before r52784, as used in Google Chrome prior to 4.0.249.78 and Apple Safari prior to 4.0.5, permits cross-origin loading of CSS stylesheets even when the stylesheet download has an incorrect MIME type and the stylesheet document is malformed, which allows remote malicious users to obtain sensitive information via a crafted document.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
apple webkit |
||
google chrome |
||
apple safari |