CVE-2015-1261: Debian Linux

Medium severity, CVSS 5.0. EPSS: 1.4% chance of exploitation in the next 30 days.

android/java/src/org/chromium/chrome/browser/WebsiteSettingsPopup.java in Google Chrome before 43.0.2357.65 on Android does not properly restrict use of a URL's fragment identifier during construction of a page-info popup, which allows remote attackers to spoof the URL bar or deliver misleading popup content via crafted text.

Affected products

  • Debian Debian Linux: version 8.0 only
  • Google Chrome: up to and including 42.0.2311.107

Published 2015-05-20. Last modified 2026-06-17.