CVE-2015-1304
object-observe.js in Google V8, as used in Google Chrome before 45.0.2454.101, does not properly restrict method calls on access-checked objects, which allows remote attackers to bypass the Same Origin Policy via a (1) observe or (2) getNotifier call.
- Google Chrome
- ≤ 45.0.2454.93
- CVSS 2.0
- 7.5 HIGH
- EPSS
- 1.8% (76th percentile)
- Weakness
- CWE-284
- NVD status
- Modified
- Published
- 2015-10-12
CVE-2015-1304 at NVD
1 known exploit for CVE-2015-1304
Proof-of-concept code and exploit modules indexed by Sploitus