CVE-2011-3881

N/A Unknown
Published: October 25, 2011 Modified: April 29, 2026
View on NVD

Description

WebKit, as used in Google Chrome before 15.0.874.102 and Android before 4.4, allows remote attackers to bypass the Same Origin Policy and conduct Universal XSS (UXSS) attacks via vectors related to (1) the DOMWindow::clear function and use of a selection object, (2) the Object::GetRealNamedPropertyInPrototypeChain function and use of an __proto__ property, (3) the HTMLPlugInImageElement::allowedToLoadFrameURL function and use of a javascript: URL, (4) incorrect origins for XSLT-generated documents in the XSLTProcessor::createDocumentFromSource function, and (5) improper handling of synchronous frame loads in the ScriptController::executeIfJavaScriptURL function.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://secunia.com/advisories/48288
Source: chrome-cve-admin@google.com
http://secunia.com/advisories/48377
Source: chrome-cve-admin@google.com
http://www.securitytracker.com/id?1026774
Source: chrome-cve-admin@google.com
http://code.google.com/p/chromium/issues/detail?id=96047
Source: af854a3a-2127-422b-91ae-364da2661108
http://code.google.com/p/chromium/issues/detail?id=96885
Source: af854a3a-2127-422b-91ae-364da2661108
http://code.google.com/p/chromium/issues/detail?id=98053
Source: af854a3a-2127-422b-91ae-364da2661108
http://code.google.com/p/chromium/issues/detail?id=99512
Source: af854a3a-2127-422b-91ae-364da2661108
http://code.google.com/p/chromium/issues/detail?id=99750
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/48288
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/48377
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securitytracker.com/id?1026774
Source: af854a3a-2127-422b-91ae-364da2661108
https://exchange.xforce.ibmcloud.com/vulnerabilities/70959
Source: af854a3a-2127-422b-91ae-364da2661108

30 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
1.8%
75th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

apple google