CVE-2015-4902
ENISA EUVD: EUVD-2015-4919 ↗
Exploited in the Wild
✓ Confirmed 0-Day
★ Google Project Zero
Triaged: March 5, 2026
1 article
EPSS Score
Source: FIRST.org · 2026-05-24
18.25%
probability
This CVE has a 18.25% probability
of being exploited in the next 30 days.
0%
Top 95.3th percentile of all CVEs
100%
CVSS v3.1
Source: NVD5.3
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Description
Project ZeroClick-to-play bypass
Affected Products
Google Project Zero
Patched
Oct. 20, 2015
Reported by
Trend Micro
Root Cause Analysis
???
Oracle Critical Patch Update October 2015
Qualys
Oct 21, 2015
Signal Intelligence
Confidence
95%
EPSS
18.25%
CVSS v3.1
5.3
Mentions
1
Last Seen
Oct 21, 2015
CNA Information
Analyst Note
Auto-imported from Google Project Zero — confirmed zero-day by definition.
Triage Info
Decided atMar 05, 2026