Access Restriction Bypass Affecting chromium package, versions [,27.0.1453.116)


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.49% (77th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-CHROMIUM-2410812
  • published26 Jan 2022
  • disclosed19 Jun 2013
  • creditUnknown

Introduced: 19 Jun 2013

CVE-2013-2866  (opens in a new tab)
CWE-264  (opens in a new tab)

How to fix?

Upgrade chromium to version 27.0.1453.116 or higher.

Overview

Affected versions of this package are vulnerable to Access Restriction Bypass. The Flash plug-in in Google Chrome before 27.0.1453.116, as used on Google Chrome OS before 27.0.1453.116 and separately, does not properly determine whether a user wishes to permit camera or microphone access by a Flash application, which allows remote attackers to obtain sensitive information from a machine's physical environment via a clickjacking attack, as demonstrated by an attack using a crafted Cascading Style Sheets (CSS) opacity property.

References

CVSS Scores

version 3.1