PT-2015-1100 · Google+4 · Google Chrome+5

Jakob

·

Published

2015-04-14

·

Updated

2025-09-29

·

CVE-2015-1242

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Google V8 versions prior to 4.2.77.8 Google Chrome versions prior to 42.0.2311.90
Description The issue allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that leverages "type confusion" in the check-elimination optimization. This is due to a problem in the ReduceTransitionElementsKind function in hydrogen-check-elimination.cc.
Recommendations For Google V8 versions prior to 4.2.77.8, update to version 4.2.77.8 or later. For Google Chrome versions prior to 42.0.2311.90, update to version 42.0.2311.90 or later. As a temporary workaround, consider restricting the execution of crafted JavaScript code to minimize the risk of exploitation.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2015-1589
BDU:2015-09970
CVE-2015-1242
DSA-3238-1
MGASA-2015-0164
OPENSUSE-SU-2024:10171-1
OPENSUSE-SU-2024:12948-1
RHSA-2015:0816
RHSA-2015_0816
USN-2570-1

Affected Products

Alt Linux
Google Chrome
Opera
Red Hat
Ubuntu
V8