CVE-2013-6643

Google Chrome < 32.0.1700.77 - Authentication Bypass

Title source: rule

Description

The OneClickSigninBubbleView::WindowClosing function in browser/ui/views/sync/one_click_signin_bubble_view.cc in Google Chrome before 32.0.1700.76 on Windows and before 32.0.1700.77 on Mac OS X and Linux allows attackers to trigger a sync with an arbitrary Google account by leveraging improper handling of the closing of an untrusted signin confirm dialog.

Scores

EPSS 0.0019
EPSS Percentile 40.2%

Classification

CWE
CWE-287
Status draft

Affected Products (5)

google/chrome < 32.0.1700.77
opensuse/opensuse
opensuse/opensuse
debian/debian_linux
debian/debian_linux

Timeline

Published Jan 16, 2014
Tracked Since Feb 18, 2026