WebKit before r53525, as used in Google Chrome before 4.0.249.89, allows remote attackers to execute arbitrary code in the Chrome sandbox via a malformed RUBY element, as demonstrated by a <ruby>><table><rt> sequence.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Google Chrome | — | Upgrade to the latest version of Google Chrome | Mar 21, 2012 | Feb 18, 2010 |
| Suse | — | Upgrade libwebkit-1_0-2-32bitUpgrade libwebkit-1_0-2Upgrade libwebkit-develUpgrade webkit-jscUpgrade libwebkit-lang | Feb 17, 2015 | Feb 18, 2010 |
| Ubuntu | — | Upgrade webkit | Nov 19, 2024 | Feb 18, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub