5
CVSSv2

CVE-2015-1266

Published: 26/06/2015 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

content/browser/webui/content_web_ui_controller_factory.cc in Google Chrome prior to 43.0.2357.130 does not properly consider the scheme in determining whether a URL is associated with a WebUI SiteInstance, which allows remote malicious users to bypass intended access restrictions via a similar URL, as demonstrated by use of gpu when there is a WebUI class for handling chrome://gpu requests.

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome

Vendor Advisories

Several security issues were fixed in Oxide ...
content/browser/webui/content_web_ui_controller_factorycc in Google Chrome before 4302357130 does not properly consider the scheme in determining whether a URL is associated with a WebUI SiteInstance, which allows remote attackers to bypass intended access restrictions via a similar URL, as demonstrated by use of gpu when there is a WebU ...