CVE-2015-1263 — Google Chrome vulnerability
Severity
6.8MEDIUMNVD
NVD4.3OSV4.3
EPSS
0.7%
top 28.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 20
Latest updateMay 17
Description
The Spellcheck API implementation in Google Chrome before 43.0.2357.65 does not use an HTTPS session for downloading a Hunspell dictionary, which allows man-in-the-middle attackers to deliver incorrect spelling suggestions or possibly have unspecified other impact via a crafted file.
CVSS vector
AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9
Affected Packages4 packages
Also affects: Debian Linux 8.0, Enterprise Linux 6.0, 6.7z
🔴Vulnerability Details
4📋Vendor Advisories
2💬Community
1Bugzilla▶
CVE-2015-1263 chromium-browser: insecure download of spellcheck dictionary in unspecified component↗2015-05-20