The FrameFetchContext::updateTimingInfoForIFrameNavigation function in core/loader/FrameFetchContext.cpp in Blink, as used in Google Chrome before 45.0.2454.85, does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to obtain sensitive information via crafted JavaScript code that leverages a history.back call.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: Chrome
Published:
Updated: 2024-08-06T04:40:18.226Z
Reserved: 2015-01-21T00:00:00
Link: CVE-2015-1300

No data.

Status : Deferred
Published: 2015-09-03T22:59:11.127
Modified: 2025-04-12T10:46:40.837
Link: CVE-2015-1300
