CVE-2009-2352 describes a cross-site scripting (XSS) vulnerability in Google Chrome versions 1.0.154.48 and earlier, as well as later versions including 2.0.172.28, 2.0.172.37, and 3.0.193.2 Beta. The flaw allows remote attackers to inject javascript: URIs into HTTP Refresh headers, leading to XSS attacks. The vulnerability has a CVSS score of 4.3, indicating a medium severity. It can be exploited remotely with medium attack complexity, potentially leading to information disclosure (partial impact on integrity) without requiring authentication. While there is no evidence of active exploitation, an exploit for a similar issue (EDB-33064) exists for an earlier Chrome version. The CVE has very low community discussion and media coverage, suggesting limited public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.0.154.48CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
0.2.149.29CPE matchmatch criteria | cpe:2.3:a:google:chrome:0.2.149.29:*:*:*:*:*:*:* | ||
0.2.149.30CPE matchmatch criteria | cpe:2.3:a:google:chrome:0.2.149.30:*:*:*:*:*:*:* | ||
0.2.152.1CPE matchmatch criteria | cpe:2.3:a:google:chrome:0.2.152.1:*:*:*:*:*:*:* | ||
0.2.153.1CPE matchmatch criteria | cpe:2.3:a:google:chrome:0.2.153.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.