PT-2014-1375 · Google+2 · Google Chrome+2
Rob Wu
·
Published
2014-08-26
·
Updated
2024-06-15
·
CVE-2014-3170
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 37.0.2062.94
Description
The issue exists due to the possibility of using the
'0' character in host names, which allows remote attackers to spoof the extension permission dialog by relying on truncation after this character. This can be exploited by attackers to manipulate the dialog, potentially leading to unauthorized access or actions.Recommendations
For Google Chrome versions prior to 37.0.2062.94, update to version 37.0.2062.94 or later to resolve the issue. As a temporary workaround, consider restricting the use of extensions that rely on host names to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Google Chrome
Suse