Vulnerability Description
Google Chrome before 42.0.2311.90 does not properly consider the interaction of page navigation with the handling of touch events and gesture events, which allows remote attackers to trigger unintended UI actions via a crafted web site that conducts a "tapjacking" attack.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Chrome | < 42.0.2311.90 | |
| Debian | Debian Linux | 8.0 |
| Canonical | Ubuntu Linux | 14.04 |
| Opensuse | Opensuse | 13.1 |
| Suse | Linux Enterprise | 12.0 |
| Redhat | Enterprise Linux Desktop | 6.0 |
| Redhat | Enterprise Linux Eus | 6.6 |
| Redhat | Enterprise Linux Server | 6.0 |
| Redhat | Enterprise Linux Server Aus | 6.6 |
| Redhat | Enterprise Linux Server Eus | 6.6 |
| Redhat | Enterprise Linux Workstation | 6.0 |
Related Weaknesses (CWE)
References
- http://googlechromereleases.blogspot.com/2015/04/stable-channel-update_14.htmlRelease Notes
- http://lists.opensuse.org/opensuse-updates/2015-04/msg00040.htmlMitigationThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2015-11/msg00024.htmlMitigationThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-0816.htmlThird Party Advisory
- http://ubuntu.com/usn/usn-2570-1Third Party Advisory
- http://www.debian.org/security/2015/dsa-3238Third Party Advisory
- http://www.securitytracker.com/id/1032209Broken LinkThird Party AdvisoryVDB Entry
- https://code.google.com/p/chromium/issues/detail?id=418402ExploitIssue TrackingVendor Advisory
- https://codereview.chromium.org/628763003Issue TrackingVendor Advisory
- https://codereview.chromium.org/660663002Issue TrackingVendor Advisory
- https://codereview.chromium.org/717573004Issue TrackingVendor Advisory
- https://codereview.chromium.org/868123002Issue TrackingVendor Advisory
- https://security.gentoo.org/glsa/201506-04Third Party Advisory
- http://googlechromereleases.blogspot.com/2015/04/stable-channel-update_14.htmlRelease Notes
- http://lists.opensuse.org/opensuse-updates/2015-04/msg00040.htmlMitigationThird Party Advisory
FAQ
What is CVE-2015-1241?
CVE-2015-1241 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Google Chrome before 42.0.2311.90 does not properly consider the interaction of page navigation with the handling of touch events and gesture events, which allows remote attackers to trigger unintende...
How severe is CVE-2015-1241?
CVE-2015-1241 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-1241?
Check the references section above for vendor advisories and patch information. Affected products include: Google Chrome, Debian Debian Linux, Canonical Ubuntu Linux, Opensuse Opensuse, Suse Linux Enterprise.