CVE-2013-0927: Google Chrome OS

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

Google Chrome OS before 26.0.1410.57 relies on a Pango pango-utils.c read_config implementation that loads the contents of the .pangorc file in the user's home directory, and the file referenced by the PANGO_RC_FILE environment variable, which allows attackers to bypass intended access restrictions via crafted configuration data.

Affected products

  • Google Chrome OS: up to and including 26.0.1410.56; version 26.0.1410.0 only; version 26.0.1410.1 only; version 26.0.1410.3 only; version 26.0.1410.4 only; version 26.0.1410.5 only; …

Published 2013-04-10. Last modified 2026-06-16.