CVE-2010-1663
Description
The Google URL Parsing Library (aka google-url or GURL) in Google Chrome before 4.1.249.1064 allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Exploits
Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.
Exploit-DB
Google Chrome 4.1.249.1059 - Cross Origin Bypass in Google URL (GURL)
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| chrome | {"endIncluding":"4.1.249.1063"} | | |
| chrome | 0.2.149.27 | | |
| chrome | 0.2.149.29 | | |
| chrome | 0.2.149.30 | | |
| chrome | 0.2.152.1 | | |
| chrome | 0.2.153.1 | | |
| chrome | 0.3.154.0 | | |
| chrome | 0.3.154.3 | | |
| chrome | 0.4.154.18 | | |
| chrome | 0.4.154.22 | | |
| chrome | 0.4.154.31 | | |
| chrome | 0.4.154.33 | | |
| chrome | 1.0.154.36 | | |
| chrome | 1.0.154.39 | | |
| chrome | 1.0.154.42 | | |
| chrome | 1.0.154.43 | | |
| chrome | 1.0.154.46 | | |
| chrome | 1.0.154.48 | | |
| chrome | 1.0.154.52 | | |
| chrome | 1.0.154.53 | | |
| chrome | 1.0.154.59 | | |
| chrome | 1.0.154.64 | | |
| chrome | 1.0.154.65 | | |
| chrome | 2.0.156.1 | | |
| chrome | 2.0.157.0 | | |
| chrome | 2.0.157.2 | | |
| chrome | 2.0.158.0 | | |
| chrome | 2.0.159.0 | | |
| chrome | 2.0.169.0 | | |
| chrome | 2.0.169.1 | | |
| chrome | 2.0.170.0 | | |
| chrome | 2.0.172 | | |
| chrome | 2.0.172.2 | | |
| chrome | 2.0.172.8 | | |
| chrome | 2.0.172.27 | | |
| chrome | 2.0.172.28 | | |
| chrome | 2.0.172.30 | | |
| chrome | 2.0.172.31 | | |
| chrome | 2.0.172.33 | | |
| chrome | 2.0.172.37 | | |
| chrome | 2.0.172.38 | | |
| chrome | 3.0.182.2 | | |
| chrome | 3.0.190.2 | | |
| chrome | 3.0.193.2 | | |
| chrome | 3.0.195.2 | | |
| chrome | 3.0.195.21 | | |
| chrome | 3.0.195.24 | | |
| chrome | 3.0.195.25 | | |
| chrome | 3.0.195.27 | | |
| chrome | 3.0.195.32 | | |
| chrome | 3.0.195.33 | | |
| chrome | 3.0.195.36 | | |
| chrome | 3.0.195.37 | | |
| chrome | 3.0.195.38 | | |
| chrome | 4.1 | | |
| chrome | 4.1.249.0 | | |
| chrome | 4.1.249.1001 | | |
| chrome | 4.1.249.1004 | | |
| chrome | 4.1.249.1006 | | |
| chrome | 4.1.249.1007 | | |
| chrome | 4.1.249.1008 | | |
| chrome | 4.1.249.1009 | | |
| chrome | 4.1.249.1010 | | |
| chrome | 4.1.249.1011 | | |
| chrome | 4.1.249.1012 | | |
| chrome | 4.1.249.1013 | | |
| chrome | 4.1.249.1014 | | |
| chrome | 4.1.249.1015 | | |
| chrome | 4.1.249.1016 | | |
| chrome | 4.1.249.1017 | | |
| chrome | 4.1.249.1018 | | |
| chrome | 4.1.249.1019 | | |
| chrome | 4.1.249.1020 | | |
| chrome | 4.1.249.1021 | | |
| chrome | 4.1.249.1022 | | |
| chrome | 4.1.249.1023 | | |
| chrome | 4.1.249.1024 | | |
| chrome | 4.1.249.1025 | | |
| chrome | 4.1.249.1026 | | |
| chrome | 4.1.249.1027 | | |
| chrome | 4.1.249.1028 | | |
| chrome | 4.1.249.1029 | | |
| chrome | 4.1.249.1030 | | |
| chrome | 4.1.249.1031 | | |
| chrome | 4.1.249.1032 | | |
| chrome | 4.1.249.1033 | | |
| chrome | 4.1.249.1034 | | |
| chrome | 4.1.249.1035 | | |
| chrome | 4.1.249.1036 | | |
| chrome | 4.1.249.1042 | | |
| chrome | 4.1.249.1045 | | |
| chrome | 4.1.249.1046 | | |
| chrome | 4.1.249.1047 | | |
| chrome | 4.1.249.1048 | | |
| chrome | 4.1.249.1049 | | |
| chrome | 4.1.249.1050 | | |
| chrome | 4.1.249.1051 | | |
| chrome | 4.1.249.1052 | | |
| chrome | 4.1.249.1053 | | |
| chrome | 4.1.249.1054 | | |
| chrome | 4.1.249.1055 | | |
| chrome | 4.1.249.1056 | | |
| chrome | 4.1.249.1057 | | |
| chrome | 4.1.249.1058 | | |
| chrome | 4.1.249.1059 | | |
| chrome | 4.1.249.1060 | | |
| chrome | 4.1.249.1061 | | |
| chrome | 4.1.249.1062 | |
References
- http://bugs.chromium.org/40445
- http://googlechromereleases.blogspot.com/2010/04/stable-update-bug-and-security-fixes.html
- http://secunia.com/advisories/39651
- http://www.vupen.com/english/advisories/2010/1016
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6813
- http://bugs.chromium.org/40445
- http://googlechromereleases.blogspot.com/2010/04/stable-update-bug-and-security-fixes.html
- http://secunia.com/advisories/39651
- http://www.vupen.com/english/advisories/2010/1016
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6813
CWEs
CWE-264
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.