CVE-2013-0885: Google Chrome

High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.

Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly restrict API privileges during interaction with the Chrome Web Store, which has unspecified impact and attack vectors.

Affected products

  • Google Chrome: before 25.0.1364.97 (fixed in 25.0.1364.97); before 25.0.1364.99 (fixed in 25.0.1364.99)
  • Opensuse Opensuse: version 12.1 only; version 12.2 only

Published 2013-02-23. Last modified 2026-06-16.