CVE-2012-1521

medium
Published 2012-05-01 · Modified 2026-04-29
CVSS v3
CVSS v2
6.8
VIR risk
6.8

Description

Use-after-free vulnerability in the XML parser in Google Chrome before 18.0.1025.168 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://googlechromereleases.blogspot.com/2012/04/stable-channel-update_30.html

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://code.google.com/p/chromium/issues/detail?id=117110

OS impact

OSVersionStatusFixed in
macos macosaffected6.0

Application impact

VendorProductVersionsFixed
gcp googlechrome{"endExcluding":"18.0.1025.168"}18.0.1025.168
appleitunes{"endExcluding":"10.7"}10.7
applesafari{"endExcluding":"6.0"}6.0

References

CWEs

CWE-416

Verify integrity in audit chain (admin only). AS-IS.