CVE-2012-2899
Publication date 5 January 2014
Last updated 24 July 2024
Ubuntu priority
Description
Google Chrome before 21.0.1180.82 on iOS makes certain incorrect calls to WebView methods that trigger use of an applewebdata: URL, which allows remote attackers to bypass the Same Origin Policy and conduct Universal XSS (UXSS) attacks via vectors involving the document.write method.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| chromium-browser | ||