The FileSystem API in Google Chrome before 40.0.2214.91 allows remote attackers to bypass the SafeBrowsing for Executable Files protection mechanism by creating a .exe file in a temporary filesystem and then referencing this file with a filesystem:http: URL.
References
Information
Published : 2015-04-19 03:59
Updated : 2017-01-02 18:59
NVD link : CVE-2015-1248
Mitre link : CVE-2015-1248
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
debian
- debian_linux
- chrome