CVE-2015-1241
Google Chrome before 42.0.2311.90 does not properly consider the interaction of page navigation with the handling of touch events and gesture events, which allows remote attackers to trigger unintended UI actions via a crafted web site that conducts a…
Does this matter?
Lower severity and a low EPSS score (2.16%). Track it; it rarely justifies an emergency change on its own.
Description
Google Chrome before 42.0.2311.90 does not properly consider the interaction of page navigation with the handling of touch events and gesture events, which allows remote attackers to trigger unintended UI actions via a crafted web site that conducts a "tapjacking" attack.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 2.16% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-1021
- Affected
- google/chrome · debian/debian linux · canonical/ubuntu linux · opensuse/opensuse · suse/linux enterprise · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server eus · redhat/enterprise linux workstation
- Source
- chrome-cve-admin@google.com
References
- http://googlechromereleases.blogspot.com/2015/04/stable-channel-update_14.htmlRelease Notes
- http://lists.opensuse.org/opensuse-updates/2015-04/msg00040.htmlMitigation, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2015-11/msg00024.htmlMitigation, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-0816.htmlThird Party Advisory
- http://ubuntu.com/usn/usn-2570-1Third Party Advisory
- http://www.debian.org/security/2015/dsa-3238Third Party Advisory
- http://www.securitytracker.com/id/1032209Broken Link, Third Party Advisory, VDB Entry
- https://code.google.com/p/chromium/issues/detail?id=418402Exploit, Issue Tracking, Vendor Advisory
- https://codereview.chromium.org/628763003Issue Tracking, Vendor Advisory
- https://codereview.chromium.org/660663002Issue Tracking, Vendor Advisory
- https://codereview.chromium.org/717573004Issue Tracking, Vendor Advisory
- https://codereview.chromium.org/868123002Issue Tracking, Vendor Advisory
- https://security.gentoo.org/glsa/201506-04Third Party Advisory
- http://googlechromereleases.blogspot.com/2015/04/stable-channel-update_14.htmlRelease Notes
- http://lists.opensuse.org/opensuse-updates/2015-04/msg00040.htmlMitigation, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2015-11/msg00024.htmlMitigation, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-0816.htmlThird Party Advisory
- http://ubuntu.com/usn/usn-2570-1Third Party Advisory
- http://www.debian.org/security/2015/dsa-3238Third Party Advisory
- http://www.securitytracker.com/id/1032209Broken Link, Third Party Advisory, VDB Entry
- https://code.google.com/p/chromium/issues/detail?id=418402Exploit, Issue Tracking, Vendor Advisory
- https://codereview.chromium.org/628763003Issue Tracking, Vendor Advisory
- https://codereview.chromium.org/660663002Issue Tracking, Vendor Advisory
- https://codereview.chromium.org/717573004Issue Tracking, Vendor Advisory
- https://codereview.chromium.org/868123002Issue Tracking, Vendor Advisory
- https://security.gentoo.org/glsa/201506-04Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.