CVE-2015-1254
Description
core/dom/Document.cpp in Blink, as used in Google Chrome before 43.0.2357.65, enables the inheritance of the designMode attribute, which allows remote attackers to bypass the Same Origin Policy by leveraging the availability of editing.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Blink's designMode inheritance in Google Chrome before 43.0.2357.65 allows bypass of Same Origin Policy via editing availability.
Vulnerability
The vulnerability exists in core/dom/Document.cpp of Blink, as used in Google Chrome before version 43.0.2357.65. The designMode attribute is improperly inherited across documents, enabling a Same Origin Policy bypass.
Exploitation
A remote attacker can exploit this by leveraging the availability of editing on a page, triggering the inheritance of the designMode attribute across origins, thus bypassing the Same Origin Policy.
Impact
Successful exploitation allows an attacker to bypass the Same Origin Policy, potentially leading to unauthorized access to cross-origin resources and information disclosure.
Mitigation
The vulnerability is fixed in Google Chrome 43.0.2357.65 and later. Users should upgrade to this version or newer. The Gentoo security advisory [1] recommends upgrading www-client/chromium to at least 43.0.2357.65. No workaround is available [1].
AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
4- cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
- Range: <43.0.2357.65
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- googlechromereleases.blogspot.com/2015/05/stable-channel-update_19.htmlnvd
- lists.opensuse.org/opensuse-updates/2015-05/msg00091.htmlnvd
- lists.opensuse.org/opensuse-updates/2015-11/msg00015.htmlnvd
- www.debian.org/security/2015/dsa-3267nvd
- www.securityfocus.com/bid/74723nvd
- www.securitytracker.com/id/1032375nvd
- code.google.com/p/chromium/issues/detailnvd
- security.gentoo.org/glsa/201506-04nvd
- src.chromium.org/viewvc/blinknvd
News mentions
0No linked articles in our index yet.