CVE-2013-6643
Google Chrome < 32.0.1700.77 - Unauthenticated Account Sync via Untrusted Signin Dialog
Title source: llmDescription
The OneClickSigninBubbleView::WindowClosing function in browser/ui/views/sync/one_click_signin_bubble_view.cc in Google Chrome before 32.0.1700.76 on Windows and before 32.0.1700.77 on Mac OS X and Linux allows attackers to trigger a sync with an arbitrary Google account by leveraging improper handling of the closing of an untrusted signin confirm dialog.
References (5)
Core 5
Core References
Patch, Vendor Advisory x_refsource_confirm
https://src.chromium.org/viewvc/chrome?revision=237115&view=revision
Mailing List, Third Party Advisory vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00008.html
Release Notes, Vendor Advisory x_refsource_confirm
http://googlechromereleases.blogspot.com/2014/01/stable-channel-update.html
Exploit, Patch, Vendor Advisory x_refsource_confirm
https://code.google.com/p/chromium/issues/detail?id=321940
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2014/dsa-2862
Scores
EPSS
0.0118
EPSS Percentile
63.8%
Details
CWE
CWE-287
Status
published
Products (5)
debian/debian_linux
7.0
debian/debian_linux
8.0
google/chrome
< 32.0.1700.77
opensuse/opensuse
12.3
opensuse/opensuse
13.1
Published
Jan 16, 2014
Tracked Since
Feb 18, 2026