CVE-2011-3081 is a use-after-free vulnerability in Google Chrome versions prior to 18.0.1025.168, impacting various Apple and Google products that incorporate Chrome's rendering engine. This critical vulnerability (CVSS 9.3) allows remote attackers to trigger a denial of service or potentially achieve arbitrary code execution through specially crafted web content related to floating elements. While there are no known public exploits or Metasploit modules, the vulnerability has garnered significant community discussion and media coverage, indicating awareness and potential for future exploitation. It is not currently listed on CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 18.0.1025.168CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 10.7CPE matchmatch criteria | cpe:2.3:a:apple:itunes:*:*:*:*:*:*:*:* | ||
< 6.0CPE matchmatch criteria | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* | ||
< 6.0CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.