CVE-2015-1211
The OriginCanAccessServiceWorkers function in content/browser/service_worker/service_worker_dispatcher_host.cc in Google Chrome before 40.0.2214.111 on Windows, OS X, and Linux and before 40.0.2214.109 on Android does not properly restrict the URI…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.15%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The OriginCanAccessServiceWorkers function in content/browser/service_worker/service_worker_dispatcher_host.cc in Google Chrome before 40.0.2214.111 on Windows, OS X, and Linux and before 40.0.2214.109 on Android does not properly restrict the URI scheme during a ServiceWorker registration, which allows remote attackers to gain privileges via a filesystem: URI.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 2.15% probability · 81th percentile
- CISA KEV
- Not listed
- Affected
- google/chrome · canonical/ubuntu linux · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux workstation · opensuse/opensuse
- Source
- chrome-cve-admin@google.com
References
- http://googlechromereleases.blogspot.com/2015/02/chrome-for-android-update.html
- http://googlechromereleases.blogspot.com/2015/02/stable-channel-update.html
- http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00005.html
- http://rhn.redhat.com/errata/RHSA-2015-0163.html
- http://secunia.com/advisories/62670
- http://secunia.com/advisories/62818
- http://secunia.com/advisories/62917
- http://secunia.com/advisories/62925
- http://security.gentoo.org/glsa/glsa-201502-13.xml
- http://www.securityfocus.com/bid/72497
- http://www.securitytracker.com/id/1031709
- http://www.ubuntu.com/usn/USN-2495-1
- https://code.google.com/p/chromium/issues/detail?id=453982
- https://codereview.chromium.org/889323002
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100717
- http://googlechromereleases.blogspot.com/2015/02/chrome-for-android-update.html
- http://googlechromereleases.blogspot.com/2015/02/stable-channel-update.html
- http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00005.html
- http://rhn.redhat.com/errata/RHSA-2015-0163.html
- http://secunia.com/advisories/62670
- http://secunia.com/advisories/62818
- http://secunia.com/advisories/62917
- http://secunia.com/advisories/62925
- http://security.gentoo.org/glsa/glsa-201502-13.xml
- http://www.securityfocus.com/bid/72497
- http://www.securitytracker.com/id/1031709
- http://www.ubuntu.com/usn/USN-2495-1
- https://code.google.com/p/chromium/issues/detail?id=453982
- https://codereview.chromium.org/889323002
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100717
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.