The WebMediaPlayerAndroid::load function in content/renderer/media/android/webmediaplayer_android.cc in Google Chrome before 36.0.1985.122 on Android does not properly interact with redirects, which allows remote attackers to bypass the Same Origin Policy via a crafted web site that hosts a video stream.
Metrics
No CVSS v4.0
No CVSS v3.1
No CVSS v3.0
Access Vector Network
Access Complexity Low
Authentication None
Confidentiality Impact Partial
Integrity Impact Partial
Availability Impact Partial
This CVE is not in the KEV list.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
Vendors | Products |
---|---|
|
Configuration 1 [-]
AND |
|
No data.
References
History
No history.

Status: PUBLISHED
Assigner: Chrome
Published: 2014-07-20T10:00:00
Updated: 2024-08-06T10:35:56.628Z
Reserved: 2014-05-03T00:00:00
Link: CVE-2014-3161

No data.

Status : Deferred
Published: 2014-07-20T11:12:50.290
Modified: 2025-04-12T10:46:40.837
Link: CVE-2014-3161

No data.