← Vulnerability feed

Vulnerability record · CVE-2010-1663 · published 3 May 2010

CVE-2010-1663: Google Chrome URL parsing library Same Origin Policy bypass

Google · Chrome

The Google URL Parsing Library (GURL) in Google Chrome before 4.1.249.1064 fails to enforce the Same Origin Policy correctly, letting a remote attacker bypass origin boundaries. Because the flaw undermines the core browser isolation model, any site the user visits could potentially read or act on content from another origin. The record gives no technical detail on the parsing error itself.

10.0 CVSS 2.0 High EPSS 54% · top 1.0% CWE-264 · Permissions and access controls
10.0CVSS 2.0 base score
54%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

The Google URL Parsing Library (aka google-url or GURL) in Google Chrome before 4.1.249.1064 allows remote attackers to bypass the Same Origin Policy via unspecified vectors.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityThe flaw breaks the Same Origin Policy with a 10.0 CVSS 2.0 score and high EPSS, but it affects only long-obsolete Chrome builds and the record lacks exploitation confirmation.

What it is

The Google URL Parsing Library (GURL) in Google Chrome before 4.1.249.1064 fails to enforce the Same Origin Policy correctly, letting a remote attacker bypass origin boundaries. Because the flaw undermines the core browser isolation model, any site the user visits could potentially read or act on content from another origin. The record gives no technical detail on the parsing error itself.

Impact

An attacker gains the ability to cross origin boundaries in the browser, which can expose authenticated session data or allow actions in the context of another site. The CVSS 2.0 vector rates full confidentiality, integrity and availability impact, though the record does not describe a concrete end effect.

Attack surface

Reached over the network through a crafted web page or URL processed by Chrome's GURL parser; no authentication is required per the AV:N/AC:L/Au:N vector. User interaction is not stated in the record, but a victim would in practice need to load attacker-controlled content in the browser.

Exploitation

Not listed in CISA KEV and no ransomware use is documented. EPSS is high (0.54067, 98.9th percentile) and a Chromium bug reference is tagged Exploit, indicating public exploit-related material exists, but the record does not confirm in-the-wild exploitation.

What to do

  • Upgrade Chrome to 4.1.249.1064 or later, the version named as the fix threshold in the description.
  • If legacy Chrome builds must remain, restrict browsing to trusted sites and isolate the browser from sensitive sessions.
  • Enforce browser version baselines through managed update policy so unsupported builds are removed.
  • Treat this as historical: verify no end-of-life Chrome 4.x builds remain in the environment.

Detection

  • Inventory endpoints for Chrome versions below 4.1.249.1064 and flag them.
  • Monitor proxy or DNS logs for Chrome user agents matching pre-4.1.249.1064 builds.
  • Review web content filtering alerts for cross-origin or URL parsing abuse patterns against legacy browsers.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2010-1663 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-10585Google Chrome V8 type confusion enables heap corruptionChrome's V8 JavaScript engine contains a type confusion flaw (CWE-843) that can lead to heap corruption when processing a crafted HTML page. It affec…KEVEPSS 5.4%analysed9.8CVE-2014-0497Adobe Flash Player integer underflow allows remote code executionAdobe Flash Player contains an integer underflow (CWE-191) that allows remote attackers to execute arbitrary code via unspecified vectors. The flaw a…KEVEPSS 100%analysed9.6CVE-2024-7971Google Chrome V8 type confusion enables heap corruptionChrome's V8 JavaScript engine contains a type confusion flaw (CWE-843) that lets a crafted HTML page corrupt the heap. It affects Chrome before 128.0…KEVEPSS 21%analysed9.6CVE-2024-5274Google Chrome V8 type confusion allows sandbox code executionGoogle Chrome before 125.0.6422.112 contains a type confusion flaw in the V8 JavaScript engine. A crafted HTML page can trigger the confusion and lea…KEVEPSS 7.5%analysed9.6CVE-2024-4947Google Chrome V8 type confusion allows sandboxed remote code executionGoogle Chrome before 125.0.6422.60 contains a type confusion flaw in the V8 JavaScript engine. A crafted HTML page can trigger the confusion and let …KEVEPSS 15%analysed9.6CVE-2024-4671Google Chrome Visuals use-after-free enables sandbox escapeCVE-2024-4671 is a use-after-free flaw in the Visuals component of Google Chrome prior to 124.0.6367.201. An attacker who has already compromised the…KEVEPSS 8.3%analysed9.6CVE-2023-6345Chrome Skia integer overflow enables sandbox escapeAn integer overflow in Skia in Google Chrome before 119.0.6045.199 lets a remote attacker who already controls the renderer process escape the browse…KEVEPSS 16%analysed9.6CVE-2023-2136Google Chrome Skia integer overflow enables sandbox escapeAn integer overflow in the Skia graphics library in Google Chrome before 112.0.5615.137 lets an attacker who already controls the renderer process es…KEVEPSS 5.7%analysed

Source: NIST National Vulnerability Database (record CVE-2010-1663), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.