CVE-2015-1211 describes a privilege escalation vulnerability in Google Chrome versions prior to 40.0.2214.111 on Windows, OS X, and Linux, and 40.0.2214.109 on Android. The flaw stems from insufficient URI scheme restrictions during ServiceWorker registration, allowing remote attackers to gain elevated privileges via a filesystem: URI. With a CVSS score of 7.5 (High), this vulnerability is easily exploitable over the network with low attack complexity, potentially leading to confidentiality, integrity, and availability impacts. There is no known active exploitation, publicly available exploit code, or Metasploit/Nuclei modules, and community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 40.0.2214.109CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:android:*:* | ||
< 40.0.2214.111CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
14.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:* | ||
14.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.10:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.