CVE-2015-1360 describes a buffer over-read vulnerability in Skia, a 2D graphics library used in Google Chrome versions prior to 40.0.2214.91. This flaw, located in the gpu/GrBitmapTextContext.cpp and gpu/GrDistanceFieldTextContext.cpp components, can be triggered by remote attackers through specially crafted data during text drawing. With a CVSS score of 7.5, this vulnerability is considered high severity, allowing for a denial of service and potentially other unspecified impacts with low attack complexity and no authentication required. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage regarding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 40.0.2214.85CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.