CVE-2014-7939: Medium severity google chrome vulnerability
Google Chrome before 40.0.2214.91, when the Harmony proxy in Google V8 is enabled, allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code with Proxy.create and console.log calls, related to HTTP responses that lack an "X-Content-Type-Options: nosniff" header.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-7939?
CVE-2014-7939 is considered a high severity vulnerability due to its ability to enable bypassing the Same Origin Policy.
How do I fix CVE-2014-7939?
To fix CVE-2014-7939, update Google Chrome or Chromium to version 40.0.2214.91 or later.
What systems are affected by CVE-2014-7939?
CVE-2014-7939 affects Google Chrome versions before 40.0.2214.91 and specific versions of Chromium and Red Hat Enterprise Linux.
What is the impact of CVE-2014-7939?
The impact of CVE-2014-7939 allows remote attackers to execute crafted JavaScript, potentially accessing sensitive information.
Is there a workaround for CVE-2014-7939?
A potential workaround for CVE-2014-7939 is to disable the Harmony proxy feature in the V8 JavaScript engine if possible.