CVE-2015-1263 describes a vulnerability in Google Chrome's Spellcheck API, specifically affecting versions prior to 43.0.2357.65, as well as Debian Chrome and Debian Linux. The flaw stems from the API's use of unencrypted HTTP for downloading Hunspell dictionaries. This allows man-in-the-middle attackers to inject malicious or incorrect spelling suggestions, potentially leading to data manipulation or other unspecified impacts. With a CVSS score of 4.3, this vulnerability is considered medium severity. It requires medium attack complexity and could result in partial integrity compromise, but does not impact confidentiality or availability. The attack vector is network-based, meaning an attacker does not need local access to the target system. There is no evidence of active exploitation, nor are there known Metasploit modules, Nuclei templates, or ExploitDB entries for this CVE. Community discussion and media coverage are minimal, indicating a low level of public awareness or concern regarding this particular vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 42.0.2311.152CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.