Vulnerability record · CVE-2010-1663 · published 3 May 2010
CVE-2010-1663: Google Chrome URL parsing library Same Origin Policy bypass
Google · Chrome
The Google URL Parsing Library (GURL) in Google Chrome before 4.1.249.1064 fails to enforce the Same Origin Policy correctly, letting a remote attacker bypass origin boundaries. Because the flaw undermines the core browser isolation model, any site the user visits could potentially read or act on content from another origin. The record gives no technical detail on the parsing error itself.
Description
The Google URL Parsing Library (aka google-url or GURL) in Google Chrome before 4.1.249.1064 allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityThe flaw breaks the Same Origin Policy with a 10.0 CVSS 2.0 score and high EPSS, but it affects only long-obsolete Chrome builds and the record lacks exploitation confirmation.
What it is
The Google URL Parsing Library (GURL) in Google Chrome before 4.1.249.1064 fails to enforce the Same Origin Policy correctly, letting a remote attacker bypass origin boundaries. Because the flaw undermines the core browser isolation model, any site the user visits could potentially read or act on content from another origin. The record gives no technical detail on the parsing error itself.
Impact
An attacker gains the ability to cross origin boundaries in the browser, which can expose authenticated session data or allow actions in the context of another site. The CVSS 2.0 vector rates full confidentiality, integrity and availability impact, though the record does not describe a concrete end effect.
Attack surface
Reached over the network through a crafted web page or URL processed by Chrome's GURL parser; no authentication is required per the AV:N/AC:L/Au:N vector. User interaction is not stated in the record, but a victim would in practice need to load attacker-controlled content in the browser.
Exploitation
Not listed in CISA KEV and no ransomware use is documented. EPSS is high (0.54067, 98.9th percentile) and a Chromium bug reference is tagged Exploit, indicating public exploit-related material exists, but the record does not confirm in-the-wild exploitation.
What to do
- Upgrade Chrome to 4.1.249.1064 or later, the version named as the fix threshold in the description.
- If legacy Chrome builds must remain, restrict browsing to trusted sites and isolate the browser from sensitive sessions.
- Enforce browser version baselines through managed update policy so unsupported builds are removed.
- Treat this as historical: verify no end-of-life Chrome 4.x builds remain in the environment.
Detection
- Inventory endpoints for Chrome versions below 4.1.249.1064 and flag them.
- Monitor proxy or DNS logs for Chrome user agents matching pre-4.1.249.1064 builds.
- Review web content filtering alerts for cross-origin or URL parsing abuse patterns against legacy browsers.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2010-1663 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2010-1663), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.