CVE-2015-1236Cross-Site Request Forgery in Google Chrome

Severity
4.3MEDIUMNVD
OSV5.0
EPSS
0.6%
top 30.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 19
Latest updateMay 17

Description

The MediaElementAudioSourceNode::process function in modules/webaudio/MediaElementAudioSourceNode.cpp in the Web Audio API implementation in Blink, as used in Google Chrome before 42.0.2311.90, allows remote attackers to bypass the Same Origin Policy and obtain sensitive audio sample values via a crafted web site containing a media element.

CVSS vector

AV:N/AC:M/C:P/I:N/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

NVDgoogle/chrome42.0.2311.60

Also affects: Debian Linux 8.0, Ubuntu Linux 14.04, 14.10, 15.04

🔴Vulnerability Details

3
GHSA
GHSA-cwv7-pxrq-5hf8: The MediaElementAudioSourceNode::process function in modules/webaudio/MediaElementAudioSourceNode2022-05-17
OSV
oxide-qt vulnerabilities2015-04-27
OSV
CVE-2015-1236: The MediaElementAudioSourceNode::process function in modules/webaudio/MediaElementAudioSourceNode2015-04-19

💥Exploits & PoCs

1
Exploit-DB
Netgear Wireless Management System 2.1.4.15 (Build 1236) - Privilege Escalation2015-09-07

📋Vendor Advisories

2
Ubuntu
Oxide vulnerabilities2015-04-27
Red Hat
chromium-browser: Cross-origin-bypass in Blink2015-04-14

💬Community

1
Bugzilla
CVE-2015-1236 chromium-browser: Cross-origin-bypass in Blink2015-04-15