Skip to main content

Google Chrome Multiple Vulnerabilities

Last Update Date: 23 May 2013 11:40 Release Date: 23 May 2013 3891 Views

RISK: Medium Risk

TYPE: Clients - Browsers

TYPE: Browsers

Multiple vulnerabilities have been identified in Google Chrome, where some have an unknown impact and others can be exploited by malicious people to disclose potentially sensitive information, conduct cross-site scripting attacks, and compromise a user's system.

  1. A use-after-free error exists in SVG.
  2. A bad cast error exists in clipboard handling.
  3. A use-after-free error exists in media loader.
  4. A use-after-free error exists in Pepper resource handling.
  5. A use-after-free error exists in widget handling. 
  6. A use-after-free error exists in speech handling.
  7. A use-after-free error exists in style resolution.
  8. Some memory safety issues exist in Web Audio.
  9. A use-after-free error exists in media loader.
  10. A use-after-free race condition error exists with workers.
  11. An unspecified error exists related to XSS Auditor, which can be exploited to extract certain data.
  12. An unspecified error exists related to drag and drop or copy and paste, which can be exploited to conduct cross-site scripting attacks.

Successful exploitation of the vulnerabilities #1 through #7, #9, and #10 may allow execution of arbitrary code. Some vulnerabilities are caused due to a bundled vulnerable version of Adobe Flash.