Endpoint Vulnerability

Security Vulnerability CVE-2013-6660 for Google Chrome

Description

The drag-and-drop implementation in Google Chrome before 33.0.1750.117 does not properly restrict the information in WebDropData data structures, which allows remote attackers to discover full pathnames via a crafted web site.

Affected Products

Google Chrome

References

CVE-2013-6660,