First published: Sun Apr 19 2015(Updated: )
Google Chrome before 42.0.2311.90 does not properly consider the interaction of page navigation with the handling of touch events and gesture events, which allows remote attackers to trigger unintended UI actions via a crafted web site that conducts a "tapjacking" attack.
Credit: cve-coordination@google.com chrome-cve-admin@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome | <=42.0.2311.60 | |
Debian Debian Linux | =8.0 | |
Ubuntu Linux | =14.04 | |
Ubuntu Linux | =14.10 | |
Ubuntu Linux | =15.04 | |
Google Chrome | <42.0.2311.90 | |
Ubuntu Linux | =14.04 | |
openSUSE | =13.1 | |
openSUSE | =13.2 | |
SUSE Linux Enterprise Server | =12.0 | |
redhat enterprise Linux desktop | =6.0 | |
redhat enterprise Linux eus | =6.6 | |
redhat enterprise Linux server | =6.0 | |
redhat enterprise Linux server aus | =6.6 | |
redhat enterprise Linux server eus | =6.6 | |
redhat enterprise Linux workstation | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1241 is rated as high severity due to its potential to allow remote attackers to perform tapjacking.
To fix CVE-2015-1241, users should update Google Chrome to version 42.0.2311.90 or later.
CVE-2015-1241 affects Google Chrome versions before 42.0.2311.90 and various Linux distributions including specific versions of Debian, Ubuntu, openSUSE, and Red Hat.
A tapjacking attack involves tricking users into clicking on invisible or disguised elements on a web page, leading to unintended actions.
No, users on the latest version of Google Chrome are not vulnerable to CVE-2015-1241.