CVE-2011-3064 describes a use-after-free vulnerability in Google Chrome versions prior to 18.0.1025.142, also affecting Apple products that embed Chrome's rendering engine such as Safari, iTunes, and iOS. This vulnerability, with a CVSS score of 7.5, allows remote attackers to cause a denial of service or potentially other unspecified impacts through specially crafted SVG clipping. While the vulnerability is easily exploitable over the network with low attack complexity and no authentication required, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed in CISA's KEV catalog. Community discussion and media coverage are minimal, suggesting limited active exploitation or public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 18.0.1025.142CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 10.7CPE matchmatch criteria | cpe:2.3:a:apple:itunes:*:*:*:*:*:*:*:* | ||
< 6.0CPE matchmatch criteria | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* | ||
< 6.0CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.