CVE-2015-1275 describes a Cross-site Scripting (XSS) vulnerability in Google Chrome for Android, specifically within the UrlUtilities.java component. This flaw allows remote attackers to inject arbitrary web script or HTML via a specially crafted "intent:" URL, impacting Google Chrome and Android platforms. With a CVSS score of 4.3, it is considered a medium-severity vulnerability, requiring moderate attack complexity (AC:M) to achieve partial integrity impact (I:P) without confidentiality or availability impact. While not listed in CISA's KEV catalog and lacking public exploit code in Metasploit or ExploitDB, it received some community and media attention at the time of its disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
13.1CPE matchmatch criteria | cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:* | ||
13.2CPE matchmatch criteria | cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:* | ||
<= 43.0.2357.134CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.