CVE-2015-1304
chromium-browser: Cross-origin bypass in V8
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
object-observe.js in Google V8, as used in Google Chrome before 45.0.2454.101, does not properly restrict method calls on access-checked objects, which allows remote attackers to bypass the Same Origin Policy via a (1) observe or (2) getNotifier call.
object-observe.js en Google V8, tal como se utiliza en Google Chrome en versiones anteriores a 45.0.2454.101, no restringe adecuadamente las llamadas a métodos en objetos de acceso verificado, lo que permite a atacantes remotos eludir la Same Origin Policy a través de una llamada (1) observe o (2) getNotifier .
Chromium is an open-source web browser, powered by WebKit. Two flaws were found in the processing of malformed web content. A web page containing malicious content could cause Chromium to bypass cross origin restrictions, and access or modify data from an unrelated web site. All Chromium users should upgrade to these updated packages, which contain Chromium version 45.0.2454.101, which corrects these issues. After installing the update, Chromium must be restarted for the changes to take effect.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-01-21 CVE Reserved
- 2015-09-30 CVE Published
- 2024-08-06 CVE Updated
- 2025-04-12 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-284: Improper Access Control
CAPEC
References (13)
URL | Tag | Source |
---|---|---|
http://googlechromereleases.blogspot.com/2015/09/stable-channel-update_24.html | X_refsource_confirm | |
http://www.securityfocus.com/bid/76844 | Vdb Entry | |
http://www.securitytracker.com/id/1033683 | Vdb Entry | |
https://chromium.googlesource.com/v8/v8/+/9b0fb52b57021473aa813f3fb99ad7384a8b86f1 | X_refsource_confirm | |
https://code.google.com/p/chromium/issues/detail?id=531891 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-security-announce/2015-10/msg00008.html | 2023-11-07 | |
http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00002.html | 2023-11-07 | |
http://rhn.redhat.com/errata/RHSA-2015-1841.html | 2023-11-07 | |
http://www.debian.org/security/2015/dsa-3376 | 2023-11-07 | |
http://www.ubuntu.com/usn/USN-2757-1 | 2023-11-07 | |
https://security.gentoo.org/glsa/201603-09 | 2023-11-07 | |
https://access.redhat.com/security/cve/CVE-2015-1304 | 2015-09-29 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1266410 | 2015-09-29 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | <= 45.0.2454.93 Search vendor "Google" for product "Chrome" and version " <= 45.0.2454.93" | - |
Affected
|