VYPR
Unrated severityNVD Advisory· Published Sep 18, 2009· Updated Jun 16, 2026

CVE-2009-3263

CVE-2009-3263

Description

Cross-site scripting (XSS) vulnerability in Google Chrome 2.x and 3.x before 3.0.195.21 allows remote attackers to inject arbitrary web script or HTML via a (1) RSS or (2) Atom feed, related to the rendering of the application/rss+xml content type as XML "active content."

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

22
  • Google/Chrome22 versions
    cpe:2.3:a:google:chrome:2.0.156.1:*:*:*:*:*:*:*+ 21 more
    • cpe:2.3:a:google:chrome:2.0.156.1:*:*:*:*:*:*:*
    • cpe:2.3:a:google:chrome:2.0.157.0:*:*:*:*:*:*:*
    • cpe:2.3:a:google:chrome:2.0.157.2:*:*:*:*:*:*:*
    • cpe:2.3:a:google:chrome:2.0.158.0:*:*:*:*:*:*:*
    • cpe:2.3:a:google:chrome:2.0.159.0:*:*:*:*:*:*:*
    • cpe:2.3:a:google:chrome:2.0.169.0:*:*:*:*:*:*:*
    • cpe:2.3:a:google:chrome:2.0.169.1:*:*:*:*:*:*:*
    • cpe:2.3:a:google:chrome:2.0.170.0:*:*:*:*:*:*:*
    • cpe:2.3:a:google:chrome:2.0.172:*:*:*:*:*:*:*
    • cpe:2.3:a:google:chrome:2.0.172.2:*:*:*:*:*:*:*
    • cpe:2.3:a:google:chrome:2.0.172.27:*:*:*:*:*:*:*
    • cpe:2.3:a:google:chrome:2.0.172.28:*:*:*:*:*:*:*
    • cpe:2.3:a:google:chrome:2.0.172.30:*:*:*:*:*:*:*
    • cpe:2.3:a:google:chrome:2.0.172.31:*:*:*:*:*:*:*
    • cpe:2.3:a:google:chrome:2.0.172.33:*:*:*:*:*:*:*
    • cpe:2.3:a:google:chrome:2.0.172.37:*:*:*:*:*:*:*
    • cpe:2.3:a:google:chrome:2.0.172.38:*:*:*:*:*:*:*
    • cpe:2.3:a:google:chrome:2.0.172.8:*:*:*:*:*:*:*
    • cpe:2.3:a:google:chrome:3.0.182.2:*:*:*:*:*:*:*
    • cpe:2.3:a:google:chrome:3.0.190.2:*:*:*:*:*:*:*
    • cpe:2.3:a:google:chrome:3.0.193.2:beta:*:*:*:*:*:*
    • (no CPE)range: >=2.0, <=3.0, <3.0.195.21

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.