HIGH
Google Chrome before 26.0.1410.43 does not ensure that an extension has the tabs (aka APIPermission::kTab) permission before providing a URL to this extension, which has unspecified impact and remote attack vectors
Published Mar 28, 2013
7.5
HIGHCVSS 2.0
EPSS 0.79%
Description
Google Chrome before 26.0.1410.43 does not ensure that an extension has the tabs (aka APIPermission::kTab) permission before providing a URL to this extension, which has unspecified impact and remote attack vectors.
Affected products
No data.
OR
- ≤ 26.0.1410.42
- 26.0.1410.0
- 26.0.1410.1
- 26.0.1410.2
- 26.0.1410.3
- 26.0.1410.4
- 26.0.1410.5
- 26.0.1410.6
- 26.0.1410.7
- 26.0.1410.8
- 26.0.1410.9
- 26.0.1410.10
- 26.0.1410.11
- 26.0.1410.12
- 26.0.1410.14
- 26.0.1410.15
- 26.0.1410.16
- 26.0.1410.17
- 26.0.1410.18
- 26.0.1410.19
- 26.0.1410.20
- 26.0.1410.21
- 26.0.1410.22
- 26.0.1410.23
- 26.0.1410.24
- 26.0.1410.25
- 26.0.1410.26
- 26.0.1410.27
- 26.0.1410.28
- 26.0.1410.29
- 26.0.1410.30
- 26.0.1410.31
- 26.0.1410.32
- 26.0.1410.33
- 26.0.1410.34
- 26.0.1410.35
- 26.0.1410.36
- 26.0.1410.37
- 26.0.1410.38
- 26.0.1410.39
- 26.0.1410.40
- 26.0.1410.41
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- http://googlechromereleases.blogspot.com/2013/03/stable-channel-update_26.html x_refsource_CONFIRM
- https://code.google.com/p/chromium/issues/detail?id=168442 x_refsource_CONFIRM
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-0936 Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16363 vdb-entrysignaturex_refsource_OVAL
| Link | Providers | Tags |
|---|---|---|
| http://googlechromereleases.blogspot.com/2013/03/stable-channel-update_26.html | x_refsource_CONFIRM | |
| https://code.google.com/p/chromium/issues/detail?id=168442 | x_refsource_CONFIRM | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-0936 | Advisory | |
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16363 | vdb-entrysignaturex_refsource_OVAL |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Chrome
Published Mar 28, 2013
Updated Aug 6, 2024
Reserved Jan 7, 2013
Link CVE-2013-0925
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2013-0936 Assigner Chrome
Published Mar 28, 2013
Updated Aug 6, 2024
Exploited since n/a
Link EUVD-2013-0936