Description
core/loader/ImageLoader.cpp in Blink, as used in Google Chrome before 44.0.2403.89, does not properly determine the V8 context of a microtask, which allows remote attackers to bypass Content Security Policy (CSP) restrictions by providing an image from an unintended source.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-3315-1 | chromium-browser security update |
EUVD |
EUVD-2015-1422 | core/loader/ImageLoader.cpp in Blink, as used in Google Chrome before 44.0.2403.89, does not properly determine the V8 context of a microtask, which allows remote attackers to bypass Content Security Policy (CSP) restrictions by providing an image from an unintended source. |
Ubuntu USN |
USN-2677-1 | Oxide vulnerabilities |
References
History
No history.
Subscriptions
Debian
Subscribe
Debian Linux
Subscribe
Google
Subscribe
Chrome
Subscribe
Opensuse
Subscribe
Opensuse
Subscribe
Redhat
Subscribe
Enterprise Linux Desktop Supplementary
Subscribe
Enterprise Linux Server Supplementary
Subscribe
Enterprise Linux Server Supplementary Eus
Subscribe
Enterprise Linux Workstation Supplementary
Subscribe
Rhel Extras
Subscribe
Status: PUBLISHED
Assigner: Chrome
Published:
Updated: 2024-08-06T04:40:18.573Z
Reserved: 2015-01-21T00:00:00.000Z
Link: CVE-2015-1281
No data.
Status : Modified
Published: 2015-07-23T00:59:10.693
Modified: 2026-05-06T22:30:45.220
Link: CVE-2015-1281
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD
Ubuntu USN