Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly restrict API privileges during interaction with the Chrome Web Store, which has unspecified impact and attack vectors.
References
Link | Resource |
---|---|
http://googlechromereleases.blogspot.com/2013/02/stable-channel-update_21.html | Release Notes Vendor Advisory |
https://code.google.com/p/chromium/issues/detail?id=172369 | Permissions Required |
http://lists.opensuse.org/opensuse-updates/2013-03/msg00045.html | Broken Link Third Party Advisory |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16255 | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Information
Published : 2013-02-23 13:55
Updated : 2022-11-18 11:59
NVD link : CVE-2013-0885
Mitre link : CVE-2013-0885
JSON object : View
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource
Products Affected
microsoft
- windows
- chrome
linux
- linux_kernel
apple
- mac_os_x
opensuse
- opensuse