Google Chrome Multiple Vulnerabilities
Last Update Date:
28 Mar 2013 11:34
Release Date:
28 Mar 2013
3856
Views
RISK: High Risk
TYPE: Clients - Browsers
Multiple vulnerabilities have been identified in Google Chrome, which can be exploited by malicious people to bypass certain security restrictions and compromise a user's system.
- A use-after-free error exists in Web Audio.
- An out-of-bounds read error exists in URL loader.
- A use-after-free error exists with pop-up windows in extensions.
- A use-after-free error exists in extension bookmarks API.
- The application does not properly ensure running isolated web sites in their own processes.
- An unspecified error exists related to memory safety in the USB Apps API.
- An error exists when verifying an extension's permissions API use in relation to file permissions.
- An error exists due to pasting active tags in certain situations.
Impact
- Remote Code Execution
- Security Restriction Bypass
System / Technologies affected
- Google Chrome 25.x
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Update to version 26.0.1410.43.
Vulnerability Identifier
- CVE-2013-0916
- CVE-2013-0917
- CVE-2013-0918
- CVE-2013-0919
- CVE-2013-0920
- CVE-2013-0921
- CVE-2013-0922
- CVE-2013-0923
- CVE-2013-0924
- CVE-2013-0925
- CVE-2013-0926
Source
Related Link
Share with