CVE-2015-1296 describes a spoofing vulnerability in Google Chrome versions prior to 45.0.2454.85. The flaw allowed attackers to display Unicode LOCK characters in the omnibox, enabling them to spoof the SSL lock icon by appending these characters to a URL, particularly in right-to-left language localizations. This vulnerability has a CVSS score of 5.0, indicating a medium severity with low attack complexity and potential for integrity impact (spoofing). While there is no evidence of active exploitation or publicly available exploit code, the vulnerability garnered some community discussion and media coverage at the time of its disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 44.0.2403CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.