CVE-2014-1733
published 2014-04-26CVE-2014-1733: The PointerCompare function in codegen.cc in Seccomp-BPF, as used in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux…
PriorityP338high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.67%
74.6th percentile
The PointerCompare function in codegen.cc in Seccomp-BPF, as used in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux, does not properly merge blocks, which might allow remote attackers to bypass intended sandbox restrictions by leveraging renderer access.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | < 34.0.1847.131 | 34.0.1847.131 | |
| chrome | < 34.0.1847.132 | 34.0.1847.132 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Chrome 34.0.1847.130/34.0.1847.131 Seccomp-BPF input validation (Nessus ID 73856 / ID 166990)
vuldb·2026-05-12·CVSS 7.5
CVE-2014-1733 [HIGH] Google Chrome 34.0.1847.130/34.0.1847.131 Seccomp-BPF input validation (Nessus ID 73856 / ID 166990)
A vulnerability was found in Google Chrome 34.0.1847.130/34.0.1847.131. It has been classified as problematic. This affects an unknown part of the component Seccomp-BPF. This manipulation causes improper input validation.
This vulnerability is handled as CVE-2014-1733. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.
GHSA
GHSA-xqh7-3533-9v4f: The PointerCompare function in codegen
ghsa_unreviewed·2022-05-17
CVE-2014-1733 [HIGH] CWE-20 GHSA-xqh7-3533-9v4f: The PointerCompare function in codegen
The PointerCompare function in codegen.cc in Seccomp-BPF, as used in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux, does not properly merge blocks, which might allow remote attackers to bypass intended sandbox restrictions by leveraging renderer access.
OSV
CVE-2014-1733: The PointerCompare function in codegen
osv·2014-04-26·CVSS 7.5
CVE-2014-1733 [HIGH] CVE-2014-1733: The PointerCompare function in codegen
The PointerCompare function in codegen.cc in Seccomp-BPF, as used in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux, does not properly merge blocks, which might allow remote attackers to bypass intended sandbox restrictions by leveraging renderer access.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://googlechromereleases.blogspot.com/2014/04/stable-channel-update_24.htmlhttp://lists.opensuse.org/opensuse-updates/2014-05/msg00049.htmlhttp://lists.opensuse.org/opensuse-updates/2014-05/msg00050.htmlhttp://secunia.com/advisories/58301http://security.gentoo.org/glsa/glsa-201408-16.xmlhttp://www.debian.org/security/2014/dsa-2920https://code.google.com/p/chromium/issues/detail?id=351103https://src.chromium.org/viewvc/chrome?revision=260157&view=revisionhttp://googlechromereleases.blogspot.com/2014/04/stable-channel-update_24.htmlhttp://lists.opensuse.org/opensuse-updates/2014-05/msg00049.htmlhttp://lists.opensuse.org/opensuse-updates/2014-05/msg00050.htmlhttp://secunia.com/advisories/58301http://security.gentoo.org/glsa/glsa-201408-16.xmlhttp://www.debian.org/security/2014/dsa-2920https://code.google.com/p/chromium/issues/detail?id=351103https://src.chromium.org/viewvc/chrome?revision=260157&view=revision
2014-04-26
Published