CVE-2015-1251
Google Chrome SpeechRecognitionClient Use-After-Free Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Use-after-free vulnerability in the SpeechRecognitionClient implementation in the Speech subsystem in Google Chrome before 43.0.2357.65 allows remote attackers to execute arbitrary code via a crafted document.
Vulnerabilidad de uso después de liberación en la implementación SpeechRecognitionClient en el subsistema Speech en Google Chrome anterior a 43.0.2357.65 permite a atacantes remotos ejecutar código arbitrario a través de un documento manipulado.
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Google Chrome. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within SpeechRecognitionClient. By manipulating a document's elements, an attacker can force a dangling pointer to be reused after it has been freed. An attacker can leverage this vulnerability to execute code under the context of the current process.
Chromium is an open-source web browser, powered by WebKit. Several flaws were found in the processing of malformed web content. A web page containing malicious content could cause Chromium to crash or, potentially, execute arbitrary code with the privileges of the user running Chromium. All Chromium users should upgrade to these updated packages, which contain Chromium version 43.0.2357.65, which corrects these issues. After installing the update, Chromium must be restarted for the changes to take effect.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-01-21 CVE Reserved
- 2015-05-19 CVE Published
- 2016-11-23 First Exploit
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-416: Use After Free
CAPEC
References (15)
URL | Tag | Source |
---|---|---|
http://blog.skylined.nl/20161123001.html | X_refsource_misc | |
http://googlechromereleases.blogspot.com/2015/05/stable-channel-update_19.html | X_refsource_confirm | |
http://seclists.org/fulldisclosure/2016/Nov/136 | Mailing List |
|
http://www.securityfocus.com/archive/1/539824/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/74723 | Vdb Entry | |
http://www.securitytracker.com/id/1032375 | Vdb Entry | |
http://zerodayinitiative.com/advisories/ZDI-15-236 | X_refsource_misc | |
https://code.google.com/p/chromium/issues/detail?id=481015 | X_refsource_confirm |
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/139874 | 2016-11-23 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-updates/2015-05/msg00091.html | 2023-11-07 | |
http://lists.opensuse.org/opensuse-updates/2015-11/msg00015.html | 2023-11-07 | |
http://www.debian.org/security/2015/dsa-3267 | 2023-11-07 | |
https://security.gentoo.org/glsa/201506-04 | 2023-11-07 | |
https://access.redhat.com/security/cve/CVE-2015-1251 | 2015-05-25 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1223258 | 2015-05-25 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | <= 42.0.2311.152 Search vendor "Google" for product "Chrome" and version " <= 42.0.2311.152" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 8.0 Search vendor "Debian" for product "Debian Linux" and version "8.0" | - |
Affected
|