CVE-2014-7939Google Chrome vulnerability

CWE-2646 documents6 sources
Severity
4.3MEDIUMNVD
EPSS
0.7%
top 28.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 22
Latest updateMay 14

Description

Google Chrome before 40.0.2214.91, when the Harmony proxy in Google V8 is enabled, allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code with Proxy.create and console.log calls, related to HTTP responses that lack an "X-Content-Type-Options: nosniff" header.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages5 packages

Also affects: Enterprise Linux 6.0, 6.6.z

🔴Vulnerability Details

3
GHSA
GHSA-m956-r3pg-f666: Google Chrome before 402022-05-14
CVEList
CVE-2014-7939: Google Chrome before 402015-01-22
OSV
CVE-2014-7939: Google Chrome before 402015-01-22

📋Vendor Advisories

1
Red Hat
chromium-browser: same-origin-bypass in V82015-01-21

💬Community

1
Bugzilla
CVE-2014-7939 chromium-browser: same-origin-bypass in V82015-01-23
CVE-2014-7939 — Google Chrome vulnerability | cvebase