WebKit before r51295, as used in Google Chrome before 4.0.249.78, presents a directory-listing page in response to an XMLHttpRequest for a file:/// URL that corresponds to a directory, which allows attackers to obtain sensitive information or possibly have unspecified other impact via a crafted local HTML document.
Get an AI-powered plain-language explanation of this vulnerability and remediation steps.
Login to generate AI explanation38 reference(s) from NVD