CVE-2015-1278 PUBLISHED

content/browser/web_contents/web_contents_impl.cc in Google Chrome before 44.0.2403.89 does not ensure that a PDF document's modal dialog is closed upon navigation to an interstitial page, which allows remote attackers to spoof URLs via a crafted document, as demonstrated by the alert_dialog.pdf document.

EPSS 1.09% · 77.8th percentile

Risk Scores

EPSS Score
1.09%
77.8th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSchromium-browser0, 29.0.1547.65-0ubuntu2, 31.0.1650.63-0ubuntu1~20131204.1

Timeline

References

Open in Interactive Console →