CVE-2009-2816
The implementation of Cross-Origin Resource Sharing (CORS) in WebKit, as used in Apple Safari before 4.0.4 and Google Chrome before 3.0.195.33, includes certain custom HTTP headers in the OPTIONS request during cross-origin operations with preflight, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via a crafted web page.
- Affected products
- Google Chrome, Safari
- Apple Safari
- < 4.0.4
- Google Chrome
- < 3.0.195.33
- Apple Iphone Os
- < 4.0
- CVSS 2.0
- 6.8 MEDIUM
- EPSS
- 1.6% (73th percentile)
- Weakness
- CWE-352
- NVD status
- Modified
- Published
- 2009-11-13
CVE-2009-2816 at NVD
2 known exploits for CVE-2009-2816
Proof-of-concept code and exploit modules indexed by Sploitus