CVE-2012-4906: Google Chrome

Medium severity, CVSS 5.0. EPSS: 3.1% chance of exploitation in the next 30 days.

Google Chrome before 18.0.1025308 on Android does not properly restrict access to file: URLs, which allows remote attackers to obtain sensitive information via unspecified vectors, as demonstrated by obtaining credential data, a different vulnerability than CVE-2012-4903.

Affected products

  • Google Chrome: up to and including 18.0.1025306

Published 2012-09-13. Last modified 2026-06-16.