CVE-2013-6659: Google Chrome
Medium severity, CVSS 6.4. EPSS: 0.8% chance of exploitation in the next 30 days.
The SSLClientSocketNSS::Core::OwnAuthCertHandler function in net/socket/ssl_client_socket_nss.cc in Google Chrome before 33.0.1750.117 does not prevent changes to server X.509 certificates during renegotiations, which allows remote SSL servers to trigger use of a new certificate chain, inconsistent with the user's expectations, by initiating a TLS renegotiation.
Affected products
- Google Chrome: up to and including 33.0.1750.116; version 33.0.1750.0 only; version 33.0.1750.1 only; version 33.0.1750.2 only; version 33.0.1750.3 only; version 33.0.1750.4 only; …
Published 2014-02-24. Last modified 2026-06-17.