Google Chrome before 28.0.1500.71 does not properly determine the
circumstances in which a renderer process can be considered a trusted
process for sign-in and subsequent sync operations, which makes it easier
for remote attackers to conduct phishing attacks via a crafted web site.
Updated: 2015-10-17 03:38:32 UTC (commit 10086)