Google Chrome < 38.0.2125.101 Multiple Vulnerabilities (Mac OS X)

High Nessus Plugin ID 78081


The remote host contains a web browser that is affected by multiple vulnerabilities.


The version of Google Chrome installed on the remote Mac OS X host is a version prior to 37.0.2062.94. It is, therefore, affected by the following vulnerabilities :

- A flaw exists in V8 and IPC that can lead to remote code execution. (CVE-2014-3188)

- Out-of-bounds read errors exist in PDFium.
(CVE-2014-3189, CVE-2014-3198)

- Use-after-free errors exist in Events, Rendering, DOM, and Web Workers. (CVE-2014-3190, CVE-2014-3191, CVE-2014-3192, CVE-2014-3194)

- A type confusion error exists in Session Management.

- Information leak vulnerabilities exist in the V8 JavaScript engine and the XSS Auditor.
(CVE-2014-3195, CVE-2014-3197)

- A security bypass vulnerability exists in the Windows Sandbox. (CVE-2014-3196)

- An error exists related to assertion of bindings in the V8 JavaScript engine. (CVE-2014-3199)

- Multiple unspecified vulnerabilities exist.


Upgrade to Google Chrome 38.0.2125.101 or later.

See Also

Plugin Details

Severity: High

ID: 78081

File Name: macosx_google_chrome_38_0_2125_101.nasl

Version: $Revision: 1.4 $

Type: local

Agent: macosx

Published: 2014/10/07

Modified: 2016/05/16

Dependencies: 70890

Risk Information

Risk Factor: High


Base Score: 9.3

Temporal Score: 9.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:ND/RL:ND/RC:ND

Vulnerability Information

CPE: cpe:/a:google:chrome

Required KB Items: MacOSX/Google Chrome/Installed

Exploit Available: false

Exploit Ease: No known exploits are available

Patch Publication Date: 2014/10/07

Vulnerability Publication Date: 2014/10/07

Reference Information

CVE: CVE-2014-3188, CVE-2014-3189, CVE-2014-3190, CVE-2014-3191, CVE-2014-3192, CVE-2014-3193, CVE-2014-3194, CVE-2014-3195, CVE-2014-3196, CVE-2014-3197, CVE-2014-3198, CVE-2014-3199, CVE-2014-3200

BID: 70262

OSVDB: 112747