Title: Google Chrome webRequest Chrome Web Store Request Interception XSS
Info
Disclosure
Jul 31, 2012
Discovery
Unknown
Dates
Exploit
Unknown
Solution
Jul 31, 2012
Description
Google Chrome contains a flaw as the webRequest API receives certain requests made by https://chrome.google.com/webstore/. With a specially crafted extension, a context-dependent attacker can intercept requests and execute script code in the context of the Web Store page e.g. causing it to install whitelisted extensions, display nag screens, and potentially use it as a stepping stone for a sandbox bypass.
Classification
Location:
Context Dependent
Attack Type:
Misconfiguration
Impact:
Loss of Integrity
Solution:
Upgrade
Exploit:
Exploit Public
Disclosure:
Vendor Verified,
Coordinated Disclosure
OSVDB:
Web Related
Solution
Upgrade to version 21.0.1180.57 or higher for Mac and Linux or 21.0.1180.60 or higher for Windows and Chrome Frame, as they have been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.