Symantec’s Thawte-branded CA issued an Extended Validation (EV) pre-certificate for the domains google.com and www.google.com on September 14. The certificate was neither requested nor authorized by Google. The issuance of the certificate was recorded in both Google-operated and DigiCert-operated logs. We have updated Chromes revocation metadata to include the public key of the misissued certificate. We currently do not have reason to believe they were at risk.”]
Source: https://security.googleblog.com/2015/09/improved-digital-certificate-security.html

