VDB
CVE-2012-1846
CVE-2012-1846
PUBLISHED
CVSS 10 CRITICAL
Google Chrome 17.0.963.66 and earlier allows remote attackers to bypass the sandbox protection mechanism by leveraging access to a sandboxed process, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2012. NOTE: the primary affected product may be clarified later; it was not identified by the researcher, who reportedly stated "it really doesn't matter if it's third-party code."
EPSS 4.24% · 90.5th percentile
Risk Scores
CVSS 2.0
10
EPSS Score
4.24%
90.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| chrome | 0 | |
| n/a | n/a | n/a |
Timeline
- Mar 22, 2012 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 10, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 18, 2023 EPSS Score
- Sep 9, 2023 EPSS Score
References
- http://www.forbes.com/sites/andygreenberg/2012/03/21/meet-the-hackers-who-sell-spies-the-tools-to-crack-your-pc-and-get-paid-six-figure-fees/ url
- oval:org.mitre.oval:def:14940 vdb
- http://pwn2own.zerodayinitiative.com/status.html technical
- http://twitter.com/vupen/statuses/177576000761237505 technical
- http://www.zdnet.com/blog/security/pwn2own-2012-google-chrome-browser-sandbox-first-to-fall/10588 technical
- https://exchange.xforce.ibmcloud.com/vulnerabilities/74324 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2012-1846 advisory
- http://www.forbes.com/sites/andygreenberg/2012/03/21/meet-the-hackers-who-sell-spies-the-tools-to-crack-your-pc-and-get-paid-six-figure-fees url