CVE-2013-2866 - CVE House
Back to Database
Status published Medium CVE-2013-2866

The Flash plug-in in Google Chrome before 27.0.1453.116, as used...

Vulnerability Description

The Flash plug-in in Google Chrome before 27.0.1453.116, as used on Google Chrome OS before 27.0.1453.116 and separately, does not properly determine whether a user wishes to permit camera or microphone access by a Flash application, which allows remote attackers to obtain sensitive information from a machine's physical environment via a clickjacking attack, as demonstrated by an attack using a crafted Cascading Style Sheets (CSS) opacity property.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2013-2866

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

chrome, chrome os
Vulnerable Versions:
0, 27.0.1453.0, 27.0.1453.1, 27.0.1453.2, 27.0.1453.3, 27.0.1453.4, 27.0.1453.5, 27.0.1453.6, 27.0.1453.7, 27.0.1453.8, 27.0.1453.9, 27.0.1453.10, 27.0.1453.11, 27.0.1453.12, 27.0.1453.13, 27.0.1453.15, 27.0.1453.34, 27.0.1453.35, 27.0.1453.36, 27.0.1453.37, 27.0.1453.38, 27.0.1453.39, 27.0.1453.40, 27.0.1453.41, 27.0.1453.42, 27.0.1453.43, 27.0.1453.44, 27.0.1453.45, 27.0.1453.46, 27.0.1453.47, 27.0.1453.49, 27.0.1453.50, 27.0.1453.51, 27.0.1453.52, 27.0.1453.54, 27.0.1453.55, 27.0.1453.56, 27.0.1453.57, 27.0.1453.58, 27.0.1453.59, 27.0.1453.60, 27.0.1453.61, 27.0.1453.62, 27.0.1453.63, 27.0.1453.64, 27.0.1453.65, 27.0.1453.66, 27.0.1453.67, 27.0.1453.68, 27.0.1453.69, 27.0.1453.70, 27.0.1453.71, 27.0.1453.72, 27.0.1453.73, 27.0.1453.74, 27.0.1453.75, 27.0.1453.76, 27.0.1453.77, 27.0.1453.78, 27.0.1453.79, 27.0.1453.80, 27.0.1453.81, 27.0.1453.82, 27.0.1453.83, 27.0.1453.84, 27.0.1453.85, 27.0.1453.86, 27.0.1453.87, 27.0.1453.88, 27.0.1453.89, 27.0.1453.90, 27.0.1453.91, 27.0.1453.93, 27.0.1453.94, 27.0.1453.102, 27.0.1453.103, 27.0.1453.104, 27.0.1453.105, 27.0.1453.106, 27.0.1453.107, 27.0.1453.108, 27.0.1453.109, 27.0.1453.110, 27.0.1453.111, 27.0.1453.112, 27.0.1453.113, 27.0.1453.114, 27.0.1453.115

Timeline

Official Publish: June 19th, 2013
Last Modified: August 6th, 2024
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.