Vulnerability in Google Chrome OS Allows Bypass of Origin Restrictions
CVE-2013-2834

Currently unrated

Key Information:

Vendor
Google
Status
Vendor
CVE Published:
16 April 2013

Summary

Google Chrome OS prior to version 26.0.1410.57 is identified as having a security flaw where it does not effectively enforce origin restrictions for the O3D and Google Talk plug-ins. This vulnerability permits remote attackers to circumvent the domain-whitelist protection mechanism via specially crafted websites, presenting a serious risk to user data and privacy.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.