CVE-2012-2899

Publication date 5 January 2014

Last updated 24 July 2024


Ubuntu priority

Description

Google Chrome before 21.0.1180.82 on iOS makes certain incorrect calls to WebView methods that trigger use of an applewebdata: URL, which allows remote attackers to bypass the Same Origin Policy and conduct Universal XSS (UXSS) attacks via vectors involving the document.write method.

Read the notes from the security team

Status

Package Ubuntu Release Status
chromium-browser 13.10 saucy
Not affected
13.04 raring
Not affected
12.10 quantal
Not affected
12.04 LTS precise
Not affected
10.04 LTS lucid Ignored end of life

Notes


mdeslaur

iOS specific