Title: Google Chrome for Android file: URI Handler Local Files Information Disclosure Weakness
Info
Disclosure
Sep 12, 2012
Discovery
Unknown
Dates
Exploit
Unknown
Solution
Sep 12, 2012
Description
Google Chrome for Android contains a flaw that may lead to unauthorized disclosure of sensitive information. The issue is triggered when using the 'file://' URI handler to open a binary file, which causes it to be copied to the 'Downloads' folder. With a malicious app, this can be exploited to disclose various sensitive information e.g. stored in the Cookies, History, Bookmarks, Cache files.
Classification
Location:
Local Access Required,
Mobile Phone / Hand-held Device
Attack Type:
Information Disclosure
Impact:
Loss of Confidentiality
Solution:
Upgrade
Exploit:
Exploit Private
Disclosure:
Vendor Verified,
Coordinated Disclosure
OSVDB:
Web Related
Solution
Upgrade to version 18.0.1025308 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.