5
CVSSv2

CVE-2015-1267

Published: 26/06/2015 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Blink, as used in Google Chrome prior to 43.0.2357.130, does not properly restrict the creation context during creation of a DOM wrapper, which allows remote malicious users to bypass the Same Origin Policy via crafted JavaScript code that uses a Blink public API, related to WebArrayBufferConverter.cpp, WebBlob.cpp, WebDOMError.cpp, and WebDOMFileSystem.cpp.

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome

Vendor Advisories

Several security issues were fixed in Oxide ...
Blink, as used in Google Chrome before 4302357130, does not properly restrict the creation context during creation of a DOM wrapper, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code that uses a Blink public API, related to WebArrayBufferConvertercpp, WebBlobcpp, WebDOMErrorcpp, and WebDOMFileSystemcp ...