CVE-2011-3060 describes an out-of-bounds read vulnerability in Google Chrome versions prior to 18.0.1025.142, stemming from improper handling of text fragments. This flaw affects Google Chrome, Apple Chrome, iPhone OS, iTunes, and Safari, potentially leading to a denial of service. Rated with a CVSS score of 6.8, this vulnerability is moderately severe, requiring medium attack complexity (AC:M) and allowing for partial impact on confidentiality, integrity, and availability (C:P/I:P/A:P) from a network-based attacker (AV:N). Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. While there is minimal community discussion and media coverage, it is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 18.0.1025.142CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 10.7CPE matchmatch criteria | cpe:2.3:a:apple:itunes:*:*:*:*:*:*:*:* | ||
< 6.0CPE matchmatch criteria | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* | ||
< 6.0CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.