CVE-2015-1211: High severity google chrome vulnerability
The OriginCanAccessServiceWorkers function in content/browser/serviceworker/serviceworkerdispatcherhost.cc in Google Chrome before 40.0.2214.111 on Windows, OS X, and Linux and before 40.0.2214.109 on Android does not properly restrict the URI scheme during a ServiceWorker registration, which allows remote attackers to gain privileges via a filesystem: URI.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1211?
CVE-2015-1211 is classified as a medium severity vulnerability due to improper URI scheme restriction during ServiceWorker registration.
How do I fix CVE-2015-1211?
To mitigate CVE-2015-1211, update Google Chrome to version 40.0.2214.111 or later.
Which versions of Google Chrome are affected by CVE-2015-1211?
CVE-2015-1211 affects Google Chrome versions prior to 40.0.2214.111 on Windows, OS X, and Linux, and prior to 40.0.2214.109 on Android.
What can happen if CVE-2015-1211 is exploited?
Exploitation of CVE-2015-1211 can allow attackers to register malicious ServiceWorkers, compromising user data and security.
Is CVE-2015-1211 relevant for all operating systems?
CVE-2015-1211 specifically affects versions of Google Chrome on Windows, OS X, Linux, and Android, while other operating systems like macOS and Linux Kernel are not vulnerable.