CVE-2015-1236
The MediaElementAudioSourceNode::process function in modules/webaudio/MediaElementAudioSourceNode.cpp in the Web Audio API implementation in Blink, as used in Google Chrome before 42.0.2311.90, allows remote attackers to bypass the Same Origin Policy and obtain sensitive audio sample values via a crafted web site containing a media element.
- Google Chrome
- ≤ 42.0.2311.60
- CVSS 2.0
- 4.3 MEDIUM
- EPSS
- 1.5% (72th percentile)
- Weakness
- CWE-264
- NVD status
- Modified
- Published
- 2015-04-19
CVE-2015-1236 at NVD
No indexed exploits for CVE-2015-1236 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2015-1236 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.