Candidate: CVE-2012-4904 PublicDate: 2012-09-13 20:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4904 https://code.google.com/p/chromium/issues/detail?id=138035 http://googlechromereleases.blogspot.com/2012/09/chrome-for-android-update.html Description: Cross-application scripting vulnerability in Google Chrome before 18.0.1025308 on Android allows remote attackers to inject arbitrary web script via unspecified vectors, as demonstrated by "Universal XSS (UXSS)" attacks against the current tab. Ubuntu-Description: Notes: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: Patches_chromium-browser: upstream_chromium-browser: needs-triage hardy_chromium-browser: DNE lucid_chromium-browser: released (23.0.1271.97-0ubuntu0.10.04.1) natty_chromium-browser: ignored (reached end-of-life) oneiric_chromium-browser: released (23.0.1271.97-0ubuntu0.11.10.1) precise_chromium-browser: released (20.0.1132.47~r144678-0ubuntu0.12.04.1) quantal_chromium-browser: not-affected (22.0.1229.79~r158531-0ubuntu1) devel_chromium-browser: not-affected (22.0.1229.79~r158531-0ubuntu1)