CVE-2014-1733: Google Chrome

High severity, CVSS 7.5. EPSS: 1.7% chance of exploitation in the next 30 days.

The PointerCompare function in codegen.cc in Seccomp-BPF, as used in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux, does not properly merge blocks, which might allow remote attackers to bypass intended sandbox restrictions by leveraging renderer access.

Affected products

  • Google Chrome: before 34.0.1847.131 (fixed in 34.0.1847.131); before 34.0.1847.132 (fixed in 34.0.1847.132)

Published 2014-04-26. Last modified 2026-06-17.