Candidate: CVE-2013-0885 PublicDate: 2013-02-23 21:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0885 http://googlechromereleases.blogspot.com/2013/02/stable-channel-update_21.html Description: Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly restrict API privileges during interaction with the Chrome Web Store, which has unspecified impact and attack vectors. Ubuntu-Description: Notes: Bugs: https://bugs.launchpad.net/ubuntu/+source/chromium-browser/+bug/1132568 Priority: medium Discovered-by: Assigned-to: chad CVSS: Patches_chromium-browser: upstream_chromium-browser: released (25.0.1364.97) hardy_chromium-browser: DNE lucid_chromium-browser: released (25.0.1364.160-0ubuntu0.10.04.1) oneiric_chromium-browser: released (25.0.1364.160-0ubuntu0.11.10.1) precise_chromium-browser: released (25.0.1364.160-0ubuntu0.12.04.1) quantal_chromium-browser: released (25.0.1364.160-0ubuntu0.12.10.1) devel_chromium-browser: released (25.0.1364.160-0ubuntu1)