CVE-2017-15397
Description
Inappropriate implementation in ChromeVox in Google Chrome OS prior to 62.0.3202.74 allowed a remote attacker in a privileged network position to observe or tamper with certain cleartext HTTP requests by leveraging that position.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
ChromeVox in Chrome OS before 62.0.3202.74 did not use SSL for certain startup HTTP requests, enabling MITM attacks.
Vulnerability
The vulnerability exists in the ChromeVox component of Chrome OS prior to version 62.0.3202.74. During the startup process, before a user logs in, ChromeVox makes network calls over cleartext HTTP instead of HTTPS. This occurs when ChromeVox is enabled on the login screen. The affected version range includes Chrome OS builds up to the fix in M62 [1].
Exploitation
An attacker in a privileged network position (e.g., on the same Wi-Fi network) can perform a man-in-the-middle attack. The attacker sets up a proxy and redirects traffic. When a victim restarts the device and enables ChromeVox on the login screen, the vulnerable HTTP requests are sent. By intercepting these requests, the attacker could inject malicious content or send a very large packet to crash the device [1].
Impact
Successful exploitation could allow the attacker to observe or tamper with cleartext HTTP requests. The impact includes potential injection of arbitrary content into Chrome OS or causing a denial of service by crashing the device. The attacker gains no authenticated access but can manipulate network-level communication [1].
Mitigation
The vendor fixed this issue in Chrome OS version 62.0.3202.74 (M62). Users should update to this or a later version. No other workarounds are documented. The bug was reported via the Chromium bug tracker and qualified for a bounty [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- www.securityfocus.com/bid/102435mitrevdb-entryx_refsource_BID
- chromereleases.googleblog.com/2017/10/stable-channel-update-for-chrome-os_27.htmlmitrex_refsource_MISC
- crbug.com/627300mitrex_refsource_MISC
- wwws.nightwatchcybersecurity.com/2018/01/01/chromeos-doesnt-always-use-ssl-during-startup-cve-2017-15397/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.