← Back

CVE-2015-1241

nvd nist
Published: Apr 19, 2015Modified: May 6, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Google Chrome before 42.0.2311.90 does not properly consider the interaction of page navigation with the handling of touch events and gesture events, which allows remote attackers to trigger unintended UI actions via a crafted web site that conducts a "tapjacking" attack.

Affected (14)

Products: Google: Chrome · Debian: Debian Linux · Canonical: Ubuntu Linux · +3 more
Show all products
1 product
Chrome
1 product
Debian Linux
1 product
Ubuntu Linux
1 product
Opensuse
1 product
Linux Enterprise
6 products
Enterprise Linux Desktop
Enterprise Linux Eus
Enterprise Linux Server
Enterprise Linux Server Aus
Enterprise Linux Server Eus
Enterprise Linux Workstation
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 42.0.2311.90
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 8.0
Configuration C
3 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 14.04
Version 14.10
Version 15.04
Configuration D
2 vulnerable
Vulnerable SoftwareAffected Versions
Opensuse
Version 13.1
Version 13.2
Configuration E
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 12.0
Configuration F
6 vulnerable

References (26)

Source: chrome-cve-admin@google.com
MitigationThird Party Advisory
Source: chrome-cve-admin@google.com
MitigationThird Party Advisory
Source: chrome-cve-admin@google.com
Third Party Advisory
Source: chrome-cve-admin@google.com
Third Party Advisory
Source: chrome-cve-admin@google.com
Third Party Advisory
Source: chrome-cve-admin@google.com
Broken LinkThird Party AdvisoryVDB Entry
Source: chrome-cve-admin@google.com
ExploitIssue TrackingVendor Advisory
Source: chrome-cve-admin@google.com
Issue TrackingVendor Advisory
Source: chrome-cve-admin@google.com
Issue TrackingVendor Advisory
Source: chrome-cve-admin@google.com
Issue TrackingVendor Advisory
Source: chrome-cve-admin@google.com
Issue TrackingVendor Advisory
Source: chrome-cve-admin@google.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.