CVE-2015-1281Google Chrome vulnerability

CWE-2547 documents7 sources
Severity
4.3MEDIUMNVD
EPSS
1.0%
top 23.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 23
Latest updateMay 14

Description

core/loader/ImageLoader.cpp in Blink, as used in Google Chrome before 44.0.2403.89, does not properly determine the V8 context of a microtask, which allows remote attackers to bypass Content Security Policy (CSP) restrictions by providing an image from an unintended source.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages4 packages

Also affects: Debian Linux 8.0, Enterprise Linux 6.0, 6.7z

🔴Vulnerability Details

3
GHSA
GHSA-hvxh-wx5q-qp62: core/loader/ImageLoader2022-05-14
CVEList
CVE-2015-1281: core/loader/ImageLoader2015-07-23
OSV
CVE-2015-1281: core/loader/ImageLoader2015-07-22

📋Vendor Advisories

2
Ubuntu
Oxide vulnerabilities2015-08-04
Red Hat
chromium-browser: CSP bypass in unspecified component2015-07-21

💬Community

1
Bugzilla
CVE-2015-1281 chromium-browser: CSP bypass in unspecified component2015-07-22
CVE-2015-1281 — Google Chrome vulnerability | cvebase