Configuration Loading Vulnerability in Google Chrome OS
CVE-2013-0927
Currently unrated
Summary
Google Chrome OS versions prior to 26.0.1410.57 are affected by a vulnerability that enables attackers to circumvent access controls by exploiting the read_config functionality in the Pango library. This flaw occurs due to the loading of user-specific configuration files, such as .pangorc and those specified by the PANGO_RC_FILE environment variable. Malicious actors can create crafted configuration data that could lead to unauthorized actions or access.
References
Timeline
Vulnerability Reserved
Vulnerability published