CVE-2015-1244: Canonical Ubuntu Linux
Medium severity, CVSS 5.0. EPSS: 1.4% chance of exploitation in the next 30 days.
The URLRequest::GetHSTSRedirect function in url_request/url_request.cc in Google Chrome before 42.0.2311.90 does not replace the ws scheme with the wss scheme whenever an HSTS Policy is active, which makes it easier for remote attackers to obtain sensitive information by sniffing the network for WebSocket traffic.
Affected products
- Canonical Ubuntu Linux: version 14.04 only; version 14.10 only; version 15.04 only
- Debian Debian Linux: version 8.0 only
- Google Chrome: up to and including 42.0.2311.60
Published 2015-04-19. Last modified 2026-06-17.