Google Chrome before 4.0.249.78 on Windows does not perform the expected encoding, escaping, and quoting for the URL in the --app argument in a desktop shortcut, which allows user-assisted remote attackers to execute arbitrary programs or obtain sensitive information by tricking a user into creating a crafted shortcut. Per: http://cwe.mitre.org/data/slices/2000.html
'Improper Encoding or Escaping of Output CWE-116'
Publication date: Fri, 19 Feb 2010 00:00:00 +0000