PT-2013-3999 · Google · Google Chrome
Publicado
2013-07-10
·
Atualizado
2017-09-19
·
CVE-2013-2879
CVSS v2.0
5.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 28.0.1500.71
Description
The issue arises from improper determination of the circumstances under which a renderer process can be considered a trusted process for sign-in and subsequent sync operations. This makes it easier for remote attackers to conduct phishing attacks via a crafted web site.
Recommendations
For versions prior to 28.0.1500.71, update to version 28.0.1500.71 or later to resolve the issue.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Google Chrome