CVE-2015-1261

medium

Description

android/java/src/org/chromium/chrome/browser/WebsiteSettingsPopup.java in Google Chrome before 43.0.2357.65 on Android does not properly restrict use of a URL's fragment identifier during construction of a page-info popup, which allows remote attackers to spoof the URL bar or deliver misleading popup content via crafted text.

References

https://codereview.chromium.org/1077483002

https://codereview.chromium.org/1056743002

https://codereview.chromium.org/1011383005

https://code.google.com/p/chromium/issues/detail?id=466351

http://www.securitytracker.com/id/1032375

http://www.securityfocus.com/bid/74723

http://www.debian.org/security/2015/dsa-3267

http://lists.opensuse.org/opensuse-updates/2015-11/msg00015.html

http://lists.opensuse.org/opensuse-updates/2015-05/msg00091.html

http://googlechromereleases.blogspot.com/2015/05/stable-channel-update_19.html

Details

Source: Mitre, NVD

Published: 2015-05-20

Updated: 2024-11-21

Risk Information

CVSS v2

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Severity: Medium