CVE-2014-1731: High severity Google Chrome vulnerability
core/html/HTMLSelectElement.cpp in the DOM implementation in Blink, as used in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux, does not properly check renderer state upon a focus event, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that leverage "type confusion" for SELECT elements.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1731?
CVE-2014-1731 has a medium severity rating and can lead to denial of service.
How do I fix CVE-2014-1731?
To fix CVE-2014-1731, update Google Chrome to version 34.0.1847.132 or later.
Which versions of Google Chrome are affected by CVE-2014-1731?
Google Chrome versions prior to 34.0.1847.131 on Windows and OS X, and prior to 34.0.1847.132 on Linux are affected.
What kind of attacks can CVE-2014-1731 facilitate?
CVE-2014-1731 can be exploited by remote attackers to cause denial of service.
Is CVE-2014-1731 relevant for Mac users?
Yes, CVE-2014-1731 is relevant for Mac users using versions of Google Chrome before 34.0.1847.131.