Google Chrome CVE-2013-6657 Weak Authentication Vulnerability

description-logoDescription

core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used in Google Chrome before 33.0.1750.117, inserts the about:blank URL during certain blocking of FORM elements within HTTP requests, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via unspecified vectors.

affected-products-logoAffected Applications

Google Chrome

CVE References

CVE-2013-6657