CVE-2015-1241
Summary
| CVE | CVE-2015-1241 |
|---|---|
| State | PUBLISHED |
| Assigner | Chrome |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-04-19 10:59:05 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Google Chrome before 42.0.2311.90 does not properly consider the interaction of page navigation with the handling of touch events and gesture events, which allows remote attackers to trigger unintended UI actions via a crafted web site that conducts a "tapjacking" attack. |
Risk And Classification
Primary CVSS: v2.0 4.3 from [email protected]
AV:N/AC:M/Au:N/C:N/I:P/A:N
Problem Types: CWE-1021 | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Canonical | Ubuntu Linux | 14.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 14.10 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 15.04 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Application | Chrome | All | All | All | All | |
| Operating System | Opensuse | Opensuse | 13.1 | All | All | All |
| Operating System | Opensuse | Opensuse | 13.2 | All | All | All |
| Operating System | Redhat | Enterprise Linux Desktop | 6.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux Eus | 6.6 | All | All | All |
| Operating System | Redhat | Enterprise Linux Server | 6.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux Server Aus | 6.6 | All | All | All |
| Operating System | Redhat | Enterprise Linux Server Eus | 6.6 | All | All | All |
| Operating System | Redhat | Enterprise Linux Workstation | 6.0 | All | All | All |
| Operating System | Suse | Linux Enterprise | 12.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Debian -- Security Information -- DSA-3238-1 chromium-browser | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Third Party Advisory |
| USN-2570-1: Oxide vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | ubuntu.com | Third Party Advisory |
| Chrome Releases: Stable Channel Update | af854a3a-2127-422b-91ae-364da2661108 | googlechromereleases.blogspot.com | Release Notes |
| Issue 628763003: Support InputRouter recycling - Code Review | af854a3a-2127-422b-91ae-364da2661108 | codereview.chromium.org | Issue Tracking, Vendor Advisory |
| Chromium: Multiple vulnerabilities (GLSA 201506-04) — Gentoo security | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | Third Party Advisory |
| Issue 418402 - chromium - Security: Cross-Page and Cross-Domain Propagation of Click events on Mobile Devices - An open-source project to help move the web forward. - Google Project Hosting | af854a3a-2127-422b-91ae-364da2661108 | code.google.com | Exploit, Issue Tracking, Vendor Advisory |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | Third Party Advisory |
| Issue 868123002: Reset gesture detection upon page navigation for Aura - Code Review | af854a3a-2127-422b-91ae-364da2661108 | codereview.chromium.org | Issue Tracking, Vendor Advisory |
| openSUSE-SU-2015:1887-1: moderate: Security update for chromium | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Mitigation, Third Party Advisory |
| Issue 717573004: [Android] Thoroughly reset gesture detection upon page navigation - Code Review | af854a3a-2127-422b-91ae-364da2661108 | codereview.chromium.org | Issue Tracking, Vendor Advisory |
| Google Chrome Multiple Bugs Let Remote Users Execute Arbitrary Code, Obtain Potentially Sensitive Information, and Bypass Same-Origin Restrictions - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Broken Link, Third Party Advisory, VDB Entry |
| Issue 660663002: Clear pending events upon main frame navigation - Code Review | af854a3a-2127-422b-91ae-364da2661108 | codereview.chromium.org | Issue Tracking, Vendor Advisory |
| openSUSE-SU-2015:0748-1: moderate: Security update for Chromium | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Mitigation, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.