CWE
20 1021
Advisory Published
Updated

CVE-2015-1241: Input Validation

First published: Sun Apr 19 2015(Updated: )

Google Chrome before 42.0.2311.90 does not properly consider the interaction of page navigation with the handling of touch events and gesture events, which allows remote attackers to trigger unintended UI actions via a crafted web site that conducts a "tapjacking" attack.

Credit: cve-coordination@google.com chrome-cve-admin@google.com

Affected SoftwareAffected VersionHow to fix
Google Chrome<42.0.2311.90
Debian Linux=8.0
Ubuntu=14.04
Ubuntu=14.10
Ubuntu=15.04
openSUSE=13.1
openSUSE=13.2
SUSE Linux Enterprise Server=12.0
Red Hat Enterprise Linux Desktop=6.0
Red Hat Enterprise Linux Server EUS=6.6
Red Hat Enterprise Linux Server=6.0
Red Hat Enterprise Linux Server=6.6
Red Hat Enterprise Linux Server=6.6
Red Hat Enterprise Linux Workstation=6.0
Google Chrome<=42.0.2311.60
Ubuntu=14.04

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2015-1241?

    CVE-2015-1241 is rated as high severity due to its potential to allow remote attackers to perform tapjacking.

  • How do I fix CVE-2015-1241?

    To fix CVE-2015-1241, users should update Google Chrome to version 42.0.2311.90 or later.

  • What platforms are affected by CVE-2015-1241?

    CVE-2015-1241 affects Google Chrome versions before 42.0.2311.90 and various Linux distributions including specific versions of Debian, Ubuntu, openSUSE, and Red Hat.

  • What is a tapjacking attack as described in CVE-2015-1241?

    A tapjacking attack involves tricking users into clicking on invisible or disguised elements on a web page, leading to unintended actions.

  • Can users still be vulnerable to CVE-2015-1241 if they are on the latest version of Google Chrome?

    No, users on the latest version of Google Chrome are not vulnerable to CVE-2015-1241.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203