CVE-2015-1236 — Cross-Site Request Forgery in Google Chrome
Severity
4.3MEDIUMNVD
OSV5.0
EPSS
0.6%
top 30.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 19
Latest updateMay 17
Description
The MediaElementAudioSourceNode::process function in modules/webaudio/MediaElementAudioSourceNode.cpp in the Web Audio API implementation in Blink, as used in Google Chrome before 42.0.2311.90, allows remote attackers to bypass the Same Origin Policy and obtain sensitive audio sample values via a crafted web site containing a media element.
CVSS vector
AV:N/AC:M/C:P/I:N/A:NExploitability: 8.6 | Impact: 2.9
Affected Packages1 packages
Also affects: Debian Linux 8.0, Ubuntu Linux 14.04, 14.10, 15.04
🔴Vulnerability Details
3💥Exploits & PoCs
1Exploit-DB
▶