The FrameFetchContext::updateTimingInfoForIFrameNavigation function in core/loader/FrameFetchContext.cpp in Blink, as used in Google Chrome before 45.0.2454.85, does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to obtain sensitive information via crafted JavaScript code that leverages a history.back call.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: Chrome
Published: 2015-09-03T22:00:00
Updated: 2024-08-06T04:40:18.226Z
Reserved: 2015-01-21T00:00:00
Link: CVE-2015-1300
Vulnrichment
No data.
NVD
Status : Modified
Published: 2015-09-03T22:59:11.127
Modified: 2024-11-21T02:25:06.613
Link: CVE-2015-1300
Redhat