CVE-2015-1298 describes a vulnerability in Google Chrome versions prior to 45.0.2454.85, specifically within the RuntimeEventRouter::OnExtensionUninstalled function. This flaw allows a user-assisted remote attacker to trigger access to an arbitrary URL. The vulnerability arises because the browser does not validate that the setUninstallURL preference corresponds to a legitimate website URL when an extension is uninstalled. The CVSS score of 4.3 indicates a medium severity, with an attack vector requiring network access and medium attack complexity, but no authentication. The potential impact is limited to partial integrity compromise (I:P), meaning an attacker could potentially redirect a user to a malicious site upon extension uninstallation. There is no evidence of active exploitation (KEV: No), nor is there publicly available exploit code in Metasploit, Nuclei, or ExploitDB. While there is some community discussion and media coverage, the overall exploitation status suggests this vulnerability is not widely targeted.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 44.0.2403CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.