4.3
CVSSv2

CVE-2015-1298

Published: 03/09/2015 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The RuntimeEventRouter::OnExtensionUninstalled function in extensions/browser/api/runtime/runtime_api.cc in Google Chrome prior to 45.0.2454.85 does not ensure that the setUninstallURL preference corresponds to the URL of a web site, which allows user-assisted remote malicious users to trigger access to an arbitrary URL via a crafted extension that is uninstalled.

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome