CVE-2015-2239

medium

Description

Google Chrome before 41.0.2272.76, when Instant Extended mode is used, does not properly consider the interaction between the "1993 search" features and restore-from-disk RELOAD transitions, which makes it easier for remote attackers to spoof the address bar for a search-results page by leveraging (1) a compromised search engine or (2) an XSS vulnerability in a search engine, a different vulnerability than CVE-2015-1231.

References

https://code.google.com/p/chromium/issues/detail?id=463349

https://code.google.com/p/chromium/issues/detail?id=256724

http://www.securityfocus.com/bid/74855

http://googlechromereleases.blogspot.com/2015/03/stable-channel-update.html

Details

Source: Mitre, NVD

Published: 2015-03-09

Risk Information

CVSS v2

Base Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 6.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Severity: Medium