CVE-2012-4904: Google Chrome

Medium severity, CVSS 4.3. EPSS: 0.7% chance of exploitation in the next 30 days.

Cross-application scripting vulnerability in Google Chrome before 18.0.1025308 on Android allows remote attackers to inject arbitrary web script via unspecified vectors, as demonstrated by "Universal XSS (UXSS)" attacks against the current tab.

Affected products

  • Google Chrome: up to and including 18.0.1025306

Published 2012-09-13. Last modified 2026-06-16.