Security Advisory
CVE-2011-3956
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
The extension implementation in Google Chrome before 17.0.963.46 does not properly handle sandboxed origins, which might allow remote attackers to bypass the Same Origin Policy via a crafted extension.