Google Chrome before 28.0.1500.71 does not properly determine the circumstances in which a renderer process can be considered a trusted process for sign-in and subsequent sync operations, which makes it easier for remote attackers to conduct phishing attacks via a crafted web site.
CVSS Details
- CVSS 3.1 Base Score: 5.4
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade dev-lang/v8.Upgrade www-client/chromium. | Oct 30, 2017 | Jul 10, 2013 |
| Google Chrome | — | Upgrade to the latest version of Google Chrome | Jul 12, 2013 | Jul 9, 2013 |
| Ubuntu | — | Upgrade chromium-browser | Nov 19, 2024 | Jul 10, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub