CVE-2014-3803

medium

Description

The SpeechInput feature in Blink, as used in Google Chrome before 35.0.1916.114, allows remote attackers to enable microphone access and obtain speech-recognition text without indication via an INPUT element with a -x-webkit-speech attribute.

References

https://src.chromium.org/viewvc/blink?revision=171373&view=revision

http://www.securityfocus.com/bid/67582

http://secunia.com/advisories/60372

http://googlechromereleases.blogspot.com/2014/05/stable-channel-update_20.html

Details

Source: Mitre, NVD

Published: 2014-05-21

Updated: 2017-01-07

Risk Information

CVSS v2

Base Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 6.5

Vector: CVSS:3.0/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H

Severity: Medium