
DescriptionWebKit, as used in Apple Safari before 5.0.4 and iOS before 4.3, does not properly handle the accessor, which allows remote attackers to bypass the Same Origin Policy and inject Cascading Style Sheets (CSS) token sequences via a crafted web site.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)


NOT-FOR-US: Webkit / if anything of this affects Chromium, the Chrome sec team will know and fix

