CVE-2014-3197: Google Chrome
Medium severity, CVSS 5.0. EPSS: 1% chance of exploitation in the next 30 days.
The NavigationScheduler::schedulePageBlock function in core/loader/NavigationScheduler.cpp in Blink, as used in Google Chrome before 38.0.2125.101, does not properly provide substitute data for pages blocked by the XSS auditor, which allows remote attackers to obtain sensitive information via a crafted web site.
Affected products
- Google Chrome: up to and including 38.0.2125.7
- Red Hat Enterprise Linux Desktop Supplementary: version 6.0 only
- Red Hat Enterprise Linux Server Supplementary: version 6.0 only
- Red Hat Enterprise Linux Server Supplementary Eus: version 6.6.z only
- Red Hat Enterprise Linux Workstation Supplementary: version 6.0 only
Published 2014-10-08. Last modified 2026-06-17.