CVE-2013-6626Google Chrome vulnerability

2 documents2 sources
Severity
4.3MEDIUMNVD
EPSS
0.6%
top 29.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 13
Latest updateMay 17

Description

The WebContentsImpl::AttachInterstitialPage function in content/browser/web_contents/web_contents_impl.cc in Google Chrome before 31.0.1650.48 does not cancel JavaScript dialogs upon generating an interstitial warning, which allows remote attackers to spoof the address bar via a crafted web site.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

NVDgoogle/chrome31.0.1650.47+43

🔴Vulnerability Details

1
GHSA
GHSA-qcfv-v56p-5c4m: The WebContentsImpl::AttachInterstitialPage function in content/browser/web_contents/web_contents_impl2022-05-17