CVE-2015-1268: Google Chrome

Medium severity, CVSS 5.0. EPSS: 2.5% chance of exploitation in the next 30 days.

bindings/scripts/v8_types.py in Blink, as used in Google Chrome before 43.0.2357.130, does not properly select a creation context for a return value's DOM wrapper, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code, as demonstrated by use of a data: URL.

Affected products

  • Google Chrome: up to and including 43.0.2357.81

Published 2015-06-26. Last modified 2026-06-17.