AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2015-1236

MEDIUM · CVSS 4.3 EPSS 1.50%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2015-04-19 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2015-1236
Severity
MEDIUM
CVSS
4.3
EPSS
1.50%
Chrome

Original Filing — NVD Description

The MediaElementAudioSourceNode::process function in modules/webaudio/MediaElementAudioSourceNode.cpp in the Web Audio API implementation in Blink, as used in Google Chrome before 42.0.2311.90, allows remote attackers to bypass the Same Origin Policy and obtain sensitive audio sample values via a crafted web site containing a media element.