CVE-2015-1236: Canonical Ubuntu Linux
Medium severity, CVSS 4.3. EPSS: 1.5% chance of exploitation in the next 30 days.
The MediaElementAudioSourceNode::process function in modules/webaudio/MediaElementAudioSourceNode.cpp in the Web Audio API implementation in Blink, as used in Google Chrome before 42.0.2311.90, allows remote attackers to bypass the Same Origin Policy and obtain sensitive audio sample values via a crafted web site containing a media element.
Affected products
- Canonical Ubuntu Linux: version 14.04 only; version 14.10 only; version 15.04 only
- Debian Debian Linux: version 8.0 only
- Google Chrome: up to and including 42.0.2311.60
Published 2015-04-19. Last modified 2026-06-17.