The V8ThrowException::createDOMException function in bindings/core/v8/V8ThrowException.cpp in the V8 bindings in Blink, as used in Google Chrome before 40.0.2214.111 on Windows, OS X, and Linux and before 40.0.2214.109 on Android, does not properly consider frame access restrictions during the throwing of an exception, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.
CVSS Details
- CVSS 3.1 Base Score: 4.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade chromium-pulseUpgrade chromium | Dec 10, 2025 | Feb 6, 2015 |
| Gentoo Linux | — | Upgrade www-client/chromium. | Oct 30, 2017 | Feb 6, 2015 |
| Google Chrome | — | Upgrade to the latest version of Google Chrome | Feb 9, 2015 | Feb 5, 2015 |
| Suse | — | Upgrade chromium | Dec 18, 2015 | Feb 6, 2015 |
| Ubuntu | — | Upgrade oxideqt-codecs-extraUpgrade oxideqt-codecsUpgrade liboxideqtcore0 | Nov 8, 2024 | Feb 6, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub