MEDIUM · 4.3

CVE-2015-1241

Google Chrome before 42.0.2311.90 does not properly consider the interaction of page navigation with the handling of touch events and gesture events, which allows remote attackers to trigger unintende...

Vulnerability Description

Google Chrome before 42.0.2311.90 does not properly consider the interaction of page navigation with the handling of touch events and gesture events, which allows remote attackers to trigger unintended UI actions via a crafted web site that conducts a "tapjacking" attack.

CVSS Score

4.3

MEDIUM

AV:N/AC:M/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
GoogleChrome< 42.0.2311.90
DebianDebian Linux8.0
CanonicalUbuntu Linux14.04
OpensuseOpensuse13.1
SuseLinux Enterprise12.0
RedhatEnterprise Linux Desktop6.0
RedhatEnterprise Linux Eus6.6
RedhatEnterprise Linux Server6.0
RedhatEnterprise Linux Server Aus6.6
RedhatEnterprise Linux Server Eus6.6
RedhatEnterprise Linux Workstation6.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-1241?

CVE-2015-1241 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Google Chrome before 42.0.2311.90 does not properly consider the interaction of page navigation with the handling of touch events and gesture events, which allows remote attackers to trigger unintende...

How severe is CVE-2015-1241?

CVE-2015-1241 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-1241?

Check the references section above for vendor advisories and patch information. Affected products include: Google Chrome, Debian Debian Linux, Canonical Ubuntu Linux, Opensuse Opensuse, Suse Linux Enterprise.