Description
object-observe.js in Google V8, as used in Google Chrome before 45.0.2454.101, does not properly restrict method calls on access-checked objects, which allows remote attackers to bypass the Same Origin Policy via a (1) observe or (2) getNotifier call.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-3376-1 | chromium-browser security update |
EUVD |
EUVD-2015-1445 | object-observe.js in Google V8, as used in Google Chrome before 45.0.2454.101, does not properly restrict method calls on access-checked objects, which allows remote attackers to bypass the Same Origin Policy via a (1) observe or (2) getNotifier call. |
Ubuntu USN |
USN-2757-1 | Oxide vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: Chrome
Published:
Updated: 2024-08-06T04:40:18.216Z
Reserved: 2015-01-21T00:00:00.000Z
Link: CVE-2015-1304
No data.
Status : Modified
Published: 2015-10-12T01:59:17.003
Modified: 2026-05-06T22:30:45.220
Link: CVE-2015-1304
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD
Ubuntu USN