Unrated severityNVD Advisory· Published Mar 9, 2012· Updated Jun 16, 2026
CVE-2011-3046
CVE-2011-3046
Description
The extension subsystem in Google Chrome before 17.0.963.78 does not properly handle history navigation, which allows remote attackers to execute arbitrary code by leveraging a "Universal XSS (UXSS)" issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6Patches
Vulnerability mechanics
References
17- code.google.com/p/chromium/issues/detailnvdVendor Advisory
- code.google.com/p/chromium/issues/detailnvdVendor Advisory
- googlechromereleases.blogspot.com/2012/03/chrome-stable-channel-update.htmlnvdRelease NotesVendor Advisory
- lists.apple.com/archives/security-announce/2012/May/msg00000.htmlnvdMailing ListThird Party Advisory
- lists.apple.com/archives/security-announce/2012/May/msg00002.htmlnvdMailing ListThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2012-03/msg00012.htmlnvdMailing ListThird Party Advisory
- security.gentoo.org/glsa/glsa-201203-19.xmlnvdThird Party Advisory
- support.apple.com/kb/HT5282nvdThird Party Advisory
- www.securityfocus.com/bid/52369nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/idnvdThird Party AdvisoryVDB Entry
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14686nvdThird Party Advisory
- plus.google.com/u/0/116651741222993143554/posts/5Eq5d9XgFqsnvdPermissions RequiredVendor Advisory
- secunia.com/advisories/47292nvdNot Applicable
- secunia.com/advisories/48321nvdNot Applicable
- secunia.com/advisories/48419nvdNot Applicable
- secunia.com/advisories/48527nvdNot Applicable
- www.zdnet.com/blog/security/cansecwest-pwnium-google-chrome-hacked-with-sandbox-bypass/10563nvdPress/Media Coverage
News mentions
0No linked articles in our index yet.