Google Chrome before 42.0.2311.90 does not always ask the user before proceeding with CONTENT_SETTINGS_TYPE_FULLSCREEN and CONTENT_SETTINGS_TYPE_MOUSELOCK changes, which allows user-assisted remote attackers to cause a denial of service (UI disruption) by constructing a crafted HTML document containing JavaScript code with requestFullScreen and requestPointerLock calls, and arranging for the user to access this document with a file: URL.
CVSS Details
- CVSS 3.1 Base Score: 4.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Google Chrome | — | Upgrade to the latest version of Google Chrome | Apr 23, 2015 | Apr 19, 2015 |
| Suse | — | Upgrade chromium-desktop-kdeUpgrade chromedriver-debuginfoUpgrade chromiumUpgrade chromedriverUpgrade chromium-debugsourceUpgrade chromium-ffmpegsumoUpgrade chromium-ffmpegsumo-debuginfoUpgrade chromium-desktop-gnomeUpgrade chromium-debuginfo | Dec 18, 2015 | Apr 19, 2015 |
| Ubuntu | — | Upgrade chromium-browser | Nov 19, 2024 | Apr 19, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub