CVE-2015-1211
published 2015-02-06CVE-2015-1211: The OriginCanAccessServiceWorkers function in content/browser/service_worker/service_worker_dispatcher_host.cc in Google Chrome before 40.0.2214.111 on…
PriorityP338high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.15%
79.9th percentile
The OriginCanAccessServiceWorkers function in content/browser/service_worker/service_worker_dispatcher_host.cc in Google Chrome before 40.0.2214.111 on Windows, OS X, and Linux and before 40.0.2214.109 on Android does not properly restrict the URI scheme during a ServiceWorker registration, which allows remote attackers to gain privileges via a filesystem: URI.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| chrome | < 40.0.2214.109 | 40.0.2214.109 | |
| chrome | < 40.0.2214.111 | 40.0.2214.111 | |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3c6g-x8mc-8hqx: The OriginCanAccessServiceWorkers function in content/browser/service_worker/service_worker_dispatcher_host
ghsa_unreviewed·2022-05-13
CVE-2015-1211 [HIGH] GHSA-3c6g-x8mc-8hqx: The OriginCanAccessServiceWorkers function in content/browser/service_worker/service_worker_dispatcher_host
The OriginCanAccessServiceWorkers function in content/browser/service_worker/service_worker_dispatcher_host.cc in Google Chrome before 40.0.2214.111 on Windows, OS X, and Linux and before 40.0.2214.109 on Android does not properly restrict the URI scheme during a ServiceWorker registration, which allows remote attackers to gain privileges via a filesystem: URI.
OSV
oxide-qt vulnerabilities
osv·2015-02-10·CVSS 7.5
CVE-2015-1209 [HIGH] oxide-qt vulnerabilities
oxide-qt vulnerabilities
A use-after-free bug was discovered in the DOM implementation in Blink. If
a user were tricked in to opening a specially crafted website, an attacker
could potentially exploit this to cause a denial of service via renderer
crash or execute arbitrary code with the privileges of the sandboxed
render process. (CVE-2015-1209)
It was discovered that V8 did not properly consider frame access
restrictions when throwing exceptions in some circumstances. If a user
were tricked in to opening a specially crafted website, an attacker could
potentially exploit this to bypass same origin restrictions.
(CVE-2015-1210)
It was discovered that Chromium did not properly restrict the URI scheme
during ServiceWorker registration. If a user were tricked in to
downloading and opening
OSV
CVE-2015-1211: The OriginCanAccessServiceWorkers function in content/browser/service_worker/service_worker_dispatcher_host
osv·2015-02-06·CVSS 7.5
CVE-2015-1211 [HIGH] CVE-2015-1211: The OriginCanAccessServiceWorkers function in content/browser/service_worker/service_worker_dispatcher_host
The OriginCanAccessServiceWorkers function in content/browser/service_worker/service_worker_dispatcher_host.cc in Google Chrome before 40.0.2214.111 on Windows, OS X, and Linux and before 40.0.2214.109 on Android does not properly restrict the URI scheme during a ServiceWorker registration, which allows remote attackers to gain privileges via a filesystem: URI.
Ubuntu
Oxide vulnerabilities
vendor_ubuntu·2015-02-10·CVSS 7.5
CVE-2015-1209 [HIGH] Oxide vulnerabilities
Title: Oxide vulnerabilities
Summary: Several security issues were fixed in Oxide.
A use-after-free bug was discovered in the DOM implementation in Blink. If
a user were tricked in to opening a specially crafted website, an attacker
could potentially exploit this to cause a denial of service via renderer
crash or execute arbitrary code with the privileges of the sandboxed
render process. (CVE-2015-1209)
It was discovered that V8 did not properly consider frame access
restrictions when throwing exceptions in some circumstances. If a user
were tricked in to opening a specially crafted website, an attacker could
potentially exploit this to bypass same origin restrictions.
(CVE-2015-1210)
It was discovered that Chromium did not properly restrict the URI scheme
during ServiceWorker registra
Red Hat
chromium-browser: privilege escalation in service workers
vendor_redhat·2015-02-04·CVSS 7.5
CVE-2015-1211 [HIGH] chromium-browser: privilege escalation in service workers
chromium-browser: privilege escalation in service workers
The OriginCanAccessServiceWorkers function in content/browser/service_worker/service_worker_dispatcher_host.cc in Google Chrome before 40.0.2214.111 on Windows, OS X, and Linux and before 40.0.2214.109 on Android does not properly restrict the URI scheme during a ServiceWorker registration, which allows remote attackers to gain privileges via a filesystem: URI.
No detection rules found.
No public exploits indexed.
http://googlechromereleases.blogspot.com/2015/02/chrome-for-android-update.htmlhttp://googlechromereleases.blogspot.com/2015/02/stable-channel-update.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00005.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0163.htmlhttp://secunia.com/advisories/62670http://secunia.com/advisories/62818http://secunia.com/advisories/62917http://secunia.com/advisories/62925http://security.gentoo.org/glsa/glsa-201502-13.xmlhttp://www.securityfocus.com/bid/72497http://www.securitytracker.com/id/1031709http://www.ubuntu.com/usn/USN-2495-1https://code.google.com/p/chromium/issues/detail?id=453982https://codereview.chromium.org/889323002https://exchange.xforce.ibmcloud.com/vulnerabilities/100717http://googlechromereleases.blogspot.com/2015/02/chrome-for-android-update.htmlhttp://googlechromereleases.blogspot.com/2015/02/stable-channel-update.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00005.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0163.htmlhttp://secunia.com/advisories/62670http://secunia.com/advisories/62818http://secunia.com/advisories/62917http://secunia.com/advisories/62925http://security.gentoo.org/glsa/glsa-201502-13.xmlhttp://www.securityfocus.com/bid/72497http://www.securitytracker.com/id/1031709http://www.ubuntu.com/usn/USN-2495-1https://code.google.com/p/chromium/issues/detail?id=453982https://codereview.chromium.org/889323002https://exchange.xforce.ibmcloud.com/vulnerabilities/100717
2015-02-06
Published