CVE-2013-2835: Medium severity chrome os vulnerability
Google Chrome OS before 26.0.1410.57 does not properly enforce origin restrictions for the O3D and Google Talk plug-ins, which allows remote attackers to bypass the domain-whitelist protection mechanism via a crafted web site, a different vulnerability than CVE-2013-2834.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2835?
CVE-2013-2835 has been classified as a high severity vulnerability due to its ability to allow remote attackers to bypass essential domain-whitelist protections.
How do I fix CVE-2013-2835?
To fix CVE-2013-2835, users must update their Google Chrome OS to version 26.0.1410.57 or later.
Which versions of Google Chrome OS are affected by CVE-2013-2835?
CVE-2013-2835 affects all versions of Google Chrome OS prior to 26.0.1410.57.
What are the potential impacts of exploiting CVE-2013-2835?
Exploiting CVE-2013-2835 could allow attackers to execute malicious actions on systems without the proper origin restrictions in place.
Is there a workaround for CVE-2013-2835?
There is no known effective workaround for CVE-2013-2835; the only solution is to apply the available update.