CVE-2013-0910: Google Chrome

High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.

Google Chrome before 25.0.1364.152 does not properly manage the interaction between the browser process and renderer processes during authorization of the loading of a plug-in, which makes it easier for remote attackers to bypass intended access restrictions via vectors involving a blocked plug-in.

Affected products

  • Google Chrome: up to and including 25.0.1364.126; version 25.0.1364.0 only; version 25.0.1364.1 only; version 25.0.1364.2 only; version 25.0.1364.3 only; version 25.0.1364.5 only; …

Published 2013-03-05. Last modified 2026-06-16.