CVE-2015-1255 is a use-after-free vulnerability in the WebAudio implementation of Google Chrome, specifically in content/renderer/media/webaudio_capturer_source.cc, affecting versions prior to 43.0.2357.65, as well as Debian Chrome and Debian Linux. This flaw allows remote attackers to trigger a denial of service through heap memory corruption or potentially achieve other unspecified impacts by improperly handling a stop action for an audio track. With a CVSS score of 6.8, it is considered medium severity, requiring medium attack complexity and potentially leading to partial confidentiality, integrity, and availability impacts. There is no evidence of active exploitation, no known public exploit code (Metasploit, Nuclei, ExploitDB), and it is not listed on the KEV catalog, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 42.0.2311.152CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.