CVE-2013-0924: Google Chrome

High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.

The extension functionality in Google Chrome before 26.0.1410.43 does not verify that use of the permissions API is consistent with file permissions, which has unspecified impact and attack vectors.

Affected products

  • Google Chrome: up to and including 26.0.1410.42; version 26.0.1410.0 only; version 26.0.1410.1 only; version 26.0.1410.2 only; version 26.0.1410.3 only; version 26.0.1410.4 only; …

Published 2013-03-28. Last modified 2026-06-16.