7.5
CVSSv2

CVE-2012-4908

Published: 13/09/2012 Updated: 14/09/2012
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Google Chrome prior to 18.0.1025308 on Android allows remote malicious users to bypass the Same Origin Policy and obtain access to local files via vectors involving a symlink.

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome

Exploits

source: wwwsecurityfocuscom/bid/55523/info Google Chrome for Android is prone to multiple vulnerabilities Attackers may exploit these issues to execute arbitrary code in the context of the browser, obtain potentially sensitive information, bypass the same-origin policy, and steal cookie-based authentication credentials; other atta ...
Chrome for Android's Same-Origin Policy for local files (file: URI) can be bypassed by using symbolic links It results in theft of Chrome's private files by malicious Android applications Version 1801025308 was released to address this vulnerability ...