CVE-2014-7939: Chromium

Medium severity, CVSS 4.3. EPSS: 2.5% chance of exploitation in the next 30 days.

Google Chrome before 40.0.2214.91, when the Harmony proxy in Google V8 is enabled, allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code with Proxy.create and console.log calls, related to HTTP responses that lack an "X-Content-Type-Options: nosniff" header.

Affected products

  • Chromium Chromium: version 40.0.2214.110 only
  • Google Chrome: up to and including 40.0.2214.85
  • Opensuse Opensuse: version 13.1 only; version 13.2 only
  • Red Hat Enterprise Linux Desktop Supplementary: version 6.0 only
  • Red Hat Enterprise Linux Server Supplementary: version 6.0 only
  • Red Hat Enterprise Linux Server Supplementary Eus: version 6.6.z only
  • Red Hat Enterprise Linux Workstation Supplementary: version 6.0 only

Published 2015-01-22. Last modified 2026-06-17.