CVE-2013-6643

Google Chrome < 32.0.1700.77 - Unauthenticated Account Sync via Untrusted Signin Dialog

Title source: llm
STIX 2.1

Description

The OneClickSigninBubbleView::WindowClosing function in browser/ui/views/sync/one_click_signin_bubble_view.cc in Google Chrome before 32.0.1700.76 on Windows and before 32.0.1700.77 on Mac OS X and Linux allows attackers to trigger a sync with an arbitrary Google account by leveraging improper handling of the closing of an untrusted signin confirm dialog.

References (5)

Core 5
Core References
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00008.html
Release Notes, Vendor Advisory x_refsource_confirm
http://googlechromereleases.blogspot.com/2014/01/stable-channel-update.html
Exploit, Patch, Vendor Advisory x_refsource_confirm
https://code.google.com/p/chromium/issues/detail?id=321940
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2014/dsa-2862

Scores

EPSS 0.0118
EPSS Percentile 63.8%

Details

CWE
CWE-287
Status published
Products (5)
debian/debian_linux 7.0
debian/debian_linux 8.0
google/chrome < 32.0.1700.77
opensuse/opensuse 12.3
opensuse/opensuse 13.1
Published Jan 16, 2014
Tracked Since Feb 18, 2026