CVE-2012-2899: Google Chrome

Medium severity, CVSS 4.3. EPSS: 0.8% chance of exploitation in the next 30 days.

Google Chrome before 21.0.1180.82 on iOS makes certain incorrect calls to WebView methods that trigger use of an applewebdata: URL, which allows remote attackers to bypass the Same Origin Policy and conduct Universal XSS (UXSS) attacks via vectors involving the document.write method.

Affected products

  • Google Chrome: up to and including 21.0.1180.81; version 21.0.1180.0 only; version 21.0.1180.1 only; version 21.0.1180.2 only; version 21.0.1180.31 only; version 21.0.1180.32 only; …

Published 2014-01-05. Last modified 2026-06-16.