Back to search
CVE-2012-1846
Published: Mar 22, 2012
Modified: Aug 6, 2024
PUBLISHED
Description
Google Chrome 17.0.963.66 and earlier allows remote attackers to bypass the sandbox protection mechanism by leveraging access to a sandboxed process, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2012. NOTE: the primary affected product may be clarified later; it was not identified by the researcher, who reportedly stated "it really doesn't matter if it's third-party code."
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://pwn2own.zerodayinitiative.com/status.html
x_refsource_MISC
http://twitter.com/vupen/statuses/177576000761237505
x_refsource_MISC
oval:org.mitre.oval:def:14940
vdb-entry
signature
x_refsource_OVAL
chrome-sandbox-security-bypass(74324)
vdb-entry
x_refsource_XF
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now