CVE-2013-2853: Google Chrome
Medium severity, CVSS 6.8. EPSS: 1.1% chance of exploitation in the next 30 days.
The HTTPS implementation in Google Chrome before 28.0.1500.71 does not ensure that headers are terminated by \r\n\r\n (carriage return, newline, carriage return, newline), which allows man-in-the-middle attackers to have an unspecified impact via vectors that trigger header truncation.
Affected products
- Google Chrome: up to and including 28.0.1500.70; version 28.0.1500.0 only; version 28.0.1500.2 only; version 28.0.1500.3 only; version 28.0.1500.4 only; version 28.0.1500.5 only; …
Published 2013-07-10. Last modified 2026-06-16.