CVE-2015-1300 describes a vulnerability in Google Chrome, specifically within the Blink rendering engine's FrameFetchContext::updateTimingInfoForIFrameNavigation function. This flaw allows remote attackers to obtain sensitive timing information from IFRAME elements via crafted JavaScript and a history.back call. The vulnerability has a CVSS score of 5.0, indicating a medium severity. It is a low-complexity attack that can be executed over the network without authentication, leading to a partial compromise of confidentiality. There is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. While there's limited community discussion and media coverage, its EPSS score suggests a very low likelihood of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 44.0.2403CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.