CVE-2015-1275Cross-site Scripting in Google Chrome

Severity
4.3MEDIUMNVD
EPSS
0.4%
top 41.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 23
Latest updateMay 14

Description

Cross-site scripting (XSS) vulnerability in org/chromium/chrome/browser/UrlUtilities.java in Google Chrome before 44.0.2403.89 on Android allows remote attackers to inject arbitrary web script or HTML via a crafted intent: URL, as demonstrated by a trailing alert(document.cookie);// substring, aka "Universal XSS (UXSS)."

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

NVDgoogle/chrome43.0.2357.134
NVDopensuse/opensuse13.1, 13.2+1

🔴Vulnerability Details

1
GHSA
GHSA-58g4-8h86-63xr: Cross-site scripting (XSS) vulnerability in org/chromium/chrome/browser/UrlUtilities2022-05-14

📋Vendor Advisories

1
Red Hat
chromium-browser: UXSS in Chrome for Android.2015-07-21

💬Community

1
Bugzilla
CVE-2015-1275 chromium-browser: UXSS in Chrome for Android.2015-07-22