CVE-2013-6623: Google Chrome

Medium severity, CVSS 4.3. EPSS: 1.4% chance of exploitation in the next 30 days.

The SVG implementation in Blink, as used in Google Chrome before 31.0.1650.48, allows remote attackers to cause a denial of service (out-of-bounds read) by leveraging the use of tree order, rather than transitive dependency order, for layout.

Affected products

  • Google Chrome: up to and including 31.0.1650.47; version 31.0.1650.0 only; version 31.0.1650.2 only; version 31.0.1650.3 only; version 31.0.1650.4 only; version 31.0.1650.5 only; …

Published 2013-11-13. Last modified 2026-06-17.