Google · Google Chrome · CVE-2015-1288
**Name of the Vulnerable Software and Affected Versions**
Google Chrome versions prior to 44.0.2403.89
**Description**
The issue is related to the Spellcheck API implementation in Google Chrome, which does not use an HTTPS session for downloading a Hunspell dictionary. This allows man-in-the-middle attackers to deliver incorrect spelling suggestions or possibly have unspecified other impact via a crafted file.
**Recommendations**
For Google Chrome versions prior to 44.0.2403.89, update to version 44.0.2403.89 or later to resolve the issue. As a temporary workaround, consider restricting access to untrusted networks to minimize the risk of exploitation.