CVE-2015-1297Google Chrome vulnerability

CWE-2547 documents5 sources
Severity
7.5HIGHNVD
EPSS
0.9%
top 24.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 3
Latest updateMay 17

Description

The WebRequest API implementation in extensions/browser/api/web_request/web_request_api.cc in Google Chrome before 45.0.2454.85 does not properly consider a request's source before accepting the request, which allows remote attackers to bypass intended access restrictions via a crafted (1) app or (2) extension.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages1 packages

NVDgoogle/chrome44.0.2403

🔴Vulnerability Details

2
GHSA
GHSA-mc69-hgc6-9g2h: The WebRequest API implementation in extensions/browser/api/web_request/web_request_api2022-05-17
OSV
CVE-2015-1297: The WebRequest API implementation in extensions/browser/api/web_request/web_request_api2015-09-03

📋Vendor Advisories

2
Red Hat
chromium-browser: Permission scoping error in WebRequest2015-09-01
Red Hat
webkitgtk: improper WebProcess IPC messages validation (WSA-2015-0001)2015-01-26

💬Community

2
Bugzilla
CVE-2015-1297 chromium-browser: Permission scoping error in WebRequest2015-09-02
Bugzilla
CVE-2014-1297 webkitgtk: improper WebProcess IPC messages validation (WSA-2015-0001)2015-01-27