CVE-2013-2835: Google Chrome OS

Medium severity, CVSS 5.0. EPSS: 0.7% chance of exploitation in the next 30 days.

Google Chrome OS before 26.0.1410.57 does not properly enforce origin restrictions for the O3D and Google Talk plug-ins, which allows remote attackers to bypass the domain-whitelist protection mechanism via a crafted web site, a different vulnerability than CVE-2013-2834.

Affected products

  • Google Chrome OS: up to and including 26.0.1410.56; version 26.0.1410.0 only; version 26.0.1410.1 only; version 26.0.1410.3 only; version 26.0.1410.4 only; version 26.0.1410.5 only; …

Published 2013-04-16. Last modified 2026-06-16.