VYPR
Unrated severityNVD Advisory· Published Feb 23, 2013· Updated Apr 29, 2026

CVE-2013-0889

CVE-2013-0889

Description

Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly enforce a user gesture requirement before proceeding with a file download, which might make it easier for remote attackers to execute arbitrary code via a crafted file.

Affected products

3
  • cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
    Range: <25.0.1364.97
  • OpenSUSE/openSUSE2 versions
    cpe:2.3:o:opensuse:opensuse:12.1:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:opensuse:opensuse:12.1:*:*:*:*:*:*:*
    • cpe:2.3:o:opensuse:opensuse:12.2:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.