The extension subsystem in Google Chrome before 17.0.963.78 does not properly handle history navigation, which allows remote attackers to execute arbitrary code by leveraging a "Universal XSS (UXSS)" issue.
| Software | From | Fixed in |
|---|---|---|
| google / chrome | - | 17.0.963.78 |
| opensuse / opensuse | 12.1 | 12.1.x |
| apple / iphone_os | - | 5.1.1 |
| apple / safari | - | 5.1.7 |