First published: Wed Jun 19 2013(Updated: )
The Flash plug-in in Google Chrome before 27.0.1453.116, as used on Google Chrome OS before 27.0.1453.116 and separately, does not properly determine whether a user wishes to permit camera or microphone access by a Flash application, which allows remote attackers to obtain sensitive information from a machine's physical environment via a clickjacking attack, as demonstrated by an attack using a crafted Cascading Style Sheets (CSS) opacity property.
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome | <=27.0.1453.115 | |
Google Chrome | =27.0.1453.0 | |
Google Chrome | =27.0.1453.1 | |
Google Chrome | =27.0.1453.2 | |
Google Chrome | =27.0.1453.3 | |
Google Chrome | =27.0.1453.4 | |
Google Chrome | =27.0.1453.5 | |
Google Chrome | =27.0.1453.6 | |
Google Chrome | =27.0.1453.7 | |
Google Chrome | =27.0.1453.8 | |
Google Chrome | =27.0.1453.9 | |
Google Chrome | =27.0.1453.10 | |
Google Chrome | =27.0.1453.11 | |
Google Chrome | =27.0.1453.12 | |
Google Chrome | =27.0.1453.13 | |
Google Chrome | =27.0.1453.15 | |
Google Chrome | =27.0.1453.34 | |
Google Chrome | =27.0.1453.35 | |
Google Chrome | =27.0.1453.36 | |
Google Chrome | =27.0.1453.37 | |
Google Chrome | =27.0.1453.38 | |
Google Chrome | =27.0.1453.39 | |
Google Chrome | =27.0.1453.40 | |
Google Chrome | =27.0.1453.41 | |
Google Chrome | =27.0.1453.42 | |
Google Chrome | =27.0.1453.43 | |
Google Chrome | =27.0.1453.44 | |
Google Chrome | =27.0.1453.45 | |
Google Chrome | =27.0.1453.46 | |
Google Chrome | =27.0.1453.47 | |
Google Chrome | =27.0.1453.49 | |
Google Chrome | =27.0.1453.50 | |
Google Chrome | =27.0.1453.51 | |
Google Chrome | =27.0.1453.52 | |
Google Chrome | =27.0.1453.54 | |
Google Chrome | =27.0.1453.55 | |
Google Chrome | =27.0.1453.56 | |
Google Chrome | =27.0.1453.57 | |
Google Chrome | =27.0.1453.58 | |
Google Chrome | =27.0.1453.59 | |
Google Chrome | =27.0.1453.60 | |
Google Chrome | =27.0.1453.61 | |
Google Chrome | =27.0.1453.62 | |
Google Chrome | =27.0.1453.63 | |
Google Chrome | =27.0.1453.64 | |
Google Chrome | =27.0.1453.65 | |
Google Chrome | =27.0.1453.66 | |
Google Chrome | =27.0.1453.67 | |
Google Chrome | =27.0.1453.68 | |
Google Chrome | =27.0.1453.69 | |
Google Chrome | =27.0.1453.70 | |
Google Chrome | =27.0.1453.71 | |
Google Chrome | =27.0.1453.72 | |
Google Chrome | =27.0.1453.73 | |
Google Chrome | =27.0.1453.74 | |
Google Chrome | =27.0.1453.75 | |
Google Chrome | =27.0.1453.76 | |
Google Chrome | =27.0.1453.77 | |
Google Chrome | =27.0.1453.78 | |
Google Chrome | =27.0.1453.79 | |
Google Chrome | =27.0.1453.80 | |
Google Chrome | =27.0.1453.81 | |
Google Chrome | =27.0.1453.82 | |
Google Chrome | =27.0.1453.83 | |
Google Chrome | =27.0.1453.84 | |
Google Chrome | =27.0.1453.85 | |
Google Chrome | =27.0.1453.86 | |
Google Chrome | =27.0.1453.87 | |
Google Chrome | =27.0.1453.88 | |
Google Chrome | =27.0.1453.89 | |
Google Chrome | =27.0.1453.90 | |
Google Chrome | =27.0.1453.91 | |
Google Chrome | =27.0.1453.93 | |
Google Chrome | =27.0.1453.94 | |
Google Chrome | =27.0.1453.102 | |
Google Chrome | =27.0.1453.103 | |
Google Chrome | =27.0.1453.104 | |
Google Chrome | =27.0.1453.105 | |
Google Chrome | =27.0.1453.106 | |
Google Chrome | =27.0.1453.107 | |
Google Chrome | =27.0.1453.108 | |
Google Chrome | =27.0.1453.109 | |
Google Chrome | =27.0.1453.110 | |
Google Chrome | =27.0.1453.111 | |
Google Chrome | =27.0.1453.112 | |
Google Chrome | =27.0.1453.113 | |
Google Chrome | =27.0.1453.114 | |
Google Chrome OS | =27.0.1453.115 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-2866 is considered a critical vulnerability as it can potentially allow remote attackers to access sensitive information through unauthorized camera or microphone access.
To fix CVE-2013-2866, update Google Chrome to version 27.0.1453.116 or later.
CVE-2013-2866 affects Google Chrome versions before 27.0.1453.116.
Yes, CVE-2013-2866 can also affect Google Chrome OS versions prior to 27.0.1453.116.
Currently, the best approach for CVE-2013-2866 is to apply the available updates to Google Chrome.