Severity
4.3MEDIUMNVD
EPSS
2.8%
top 13.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 19
Latest updateMay 17

Description

Google Chrome before 42.0.2311.90 does not properly consider the interaction of page navigation with the handling of touch events and gesture events, which allows remote attackers to trigger unintended UI actions via a crafted web site that conducts a "tapjacking" attack.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages5 packages

Also affects: Debian Linux 8.0, Linux Enterprise 12.0, Ubuntu Linux 14.04, 14.10, 15.04, Enterprise Linux 6.6

🔴Vulnerability Details

3
GHSA
GHSA-5rxr-h5mf-7p7w: Google Chrome before 422022-05-17
CVEList
CVE-2015-1241: Google Chrome before 422015-04-19
OSV
CVE-2015-1241: Google Chrome before 422015-04-19

📋Vendor Advisories

3
Ubuntu
Oxide vulnerabilities2015-04-27
Red Hat
chromium-browser: tap-jacking vulnerability2015-04-14
Red Hat
gcc: Predictable randomness from std::random_device2015-02-20

💬Community

1
Bugzilla
CVE-2015-1241 chromium-browser: tap-jacking vulnerability2015-04-15
CVE-2015-1241 — UI Misrepresentation / Clickjacking | cvebase