CVEs Blog | G5 Cyber Security

CVE-2015-1281 – core/loader/ImageLoader.cpp in Blink, as used in Google Chrome before 44.

core/loader/ImageLoader.cpp in Blink, as used in Google Chrome before 44.0.2403.89, does not properly determine the V8 context of a microtask, which allows remote attackers to bypass Content Security Policy (CSP) restrictions by providing an image from an unintended source.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1281

Reference (s):

Exit mobile version