CVE-2013-6662

Plain English Summary

AI-powered analysis for quick understanding

This vulnerability allows an attacker to potentially intercept and decrypt secure communications in Google Chrome by exploiting the way the browser caches TLS sessions before checking if the website's certificate is valid. For this to work, the attacker needs to be able to trick the browser into using a cached session, which could happen on compromised networks or through malicious websites.

Technical Description

Google Chrome caches TLS sessions before certificate validation occurs.

CVSS Vector Analysis

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionRequired
Confidentiality ImpactNone
Integrity ImpactHigh
Availability ImpactNone
ScopeUnchanged

Vector String

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Exploit Resources

Search for proof-of-concept code and exploit modules

Official References

Est. Bounty
$931($500-$1K)
Vendor Response
Grade FPatched in 3237 days

Quick Information

Published

Apr 13, 2017

almost 9 years ago

Last Modified

Feb 23, 2026

about 1 month ago

Vendor

google

Product

chrome