CVE-2010-2299 describes a critical type confusion vulnerability in Google Chrome versions prior to 5.0.375.70. This flaw, located in the Clipboard::DispatchObject function, could allow remote attackers to execute arbitrary code by sending crafted data from the renderer process, specifically when handling CBF_SMBITMAP objects within a ViewHostMsg_ClipboardWriteObjectsAsync message. With a CVSS score of 10.0, this vulnerability is considered highly severe, indicating an easily exploitable network-based attack with complete compromise of confidentiality, integrity, and availability. The FAUCET Risk Score of 86/100 further emphasizes its critical nature. Despite its severity, there is no evidence of active exploitation (KEV: No), and no public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. Furthermore, there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.0.375.70CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.