CVE-2015-1224 describes an out-of-bounds read vulnerability in the VpxVideoDecoder::VpxDecode function within Google Chrome versions prior to 41.0.2272.76. This flaw arises from the decoder's failure to verify identical alpha-plane and image dimensions when processing VPx video data. A remote attacker could exploit this by crafting malicious VPx video, leading to a denial of service. While the CVSS score is 5.0 (medium severity) with a low attack complexity, indicating a potential for denial of service, there is no evidence of active exploitation, publicly available exploit code, or significant community discussion or media coverage beyond a single article.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 40.0.2214.115CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.