CVE-2015-6759 describes an information disclosure vulnerability in the Blink rendering engine, specifically within the shouldTreatAsUniqueOrigin function in Google Chrome versions prior to 46.0.2490.71. This flaw allows remote attackers to bypass origin checks for LocalStorage resources via specially crafted blob: URLs, potentially leading to the exposure of sensitive user data. Rated with a CVSS score of 5.0 (medium severity), it has a low attack complexity and requires no authentication, but only impacts confidentiality. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion, and it is not listed in CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 45.0.2454.101CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.