Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2011-3056

22
FAUCET Score

CVE-2011-3056 describes a Same Origin Policy bypass vulnerability in Google Chrome versions prior to 17.0.963.83, also affecting Apple and OpenSUSE products. This medium-severity flaw, with a CVSS score of 6.8, could allow remote attackers to access sensitive information, modify data, and potentially impact system availability through a "magic iframe" attack. While no public exploit code or active exploitation has been identified, the vulnerability has garnered some community discussion and media coverage, indicating awareness within the cybersecurity community.

Impacted Technologies

VendorProductVersion(s)CPE
< 17.0.963.83CPE matchmatch criteria
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
12.1CPE matchmatch criteria
cpe:2.3:o:opensuse:opensuse:12.1:*:*:*:*:*:*:*
< 5.1.7CPE matchmatch criteria
cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
< 5.1.1CPE matchmatch criteria
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

6.8MEDIUM

AV:N/AC:M/Au:N/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
1.33%
Probability of exploitation in next 30 days
EPSS Percentile
68.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0133 is in the 38th percentile among its peer group of 19,955 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2011-3056Moderate

Webkitgtk: google chrome update [21-March-2012]

Mar 21, 2012

References

code.google.com / p/chromium/issues/detail
Vendor Advisory
googlechromereleases.blogspot.com / 2012/03/stable-channel-update_21.html
Vendor Advisory
lists.apple.com / archives/security-announce/2012/May/msg00000.html
Mailing ListThird Party Advisory
lists.apple.com / archives/security-announce/2012/May/msg00002.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2012-04/msg00000.html
Mailing ListThird Party Advisory
osvdb.org / 80294
Broken Link
osvdb.org / 81794
Broken Link
secunia.com / advisories/47292
Not Applicable
secunia.com / advisories/48512
Not Applicable
secunia.com / advisories/48527
Not Applicable
security.gentoo.org / glsa/glsa-201203-19.xml
Third Party Advisory
exchange.xforce.ibmcloud.com / vulnerabilities/74216
Third Party AdvisoryVDB Entry
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14962
Third Party Advisory
support.apple.com / kb/HT5282
Third Party Advisory
securityfocus.com / bid/52674
Third Party AdvisoryVDB Entry
securitytracker.com / id
Third Party AdvisoryVDB Entry