4.3 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:N/AC:M/Au:N/C:P/I:N/A:N
6 Medium
AI Score
Confidence
Low
0.024 Low
EPSS
Percentile
89.8%
The SpeechInput feature in Blink, as used in Google Chrome before 35.0.1916.114, allows remote attackers to enable microphone access and obtain speech-recognition text without indication via an INPUT element with a -x-webkit-speech attribute.
blog.guya.net/2014/04/07/to-listen-without-consent-abusing-the-html5-speech/
googlechromereleases.blogspot.com/2014/05/stable-channel-update_20.html
secunia.com/advisories/60372
www.securityfocus.com/bid/67582
code.google.com/p/chromium/issues/detail?id=360448
src.chromium.org/viewvc/blink?revision=171373&view=revision