The Public Key Pinning (PKP) implementation in Google Chrome before 36.0.1985.143 on Windows, OS X, and Linux, and before 36.0.1985.135 on Android, does not correctly consider the properties of SPDY connections, which allows remote attackers to obtain sensitive information by leveraging the use of multiple domain names.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade www-client/chromium. | Oct 30, 2017 | Aug 13, 2014 |
| Google Chrome | — | Upgrade to the latest version of Google Chrome | Aug 15, 2014 | Aug 12, 2014 |
| Suse | — | Upgrade chromium | May 20, 2018 | Aug 13, 2014 |
| Ubuntu | — | Upgrade oxideqt-codecsUpgrade liboxideqtcore0Upgrade oxideqt-codecs-extra | Nov 8, 2024 | Aug 13, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub