CVE-2017-5013

MEDIUM

Google Chrome <56.0.2924.76 - XSS

Title source: llm

Description

Google Chrome prior to 56.0.2924.76 for Linux incorrectly handled new tab page navigations in non-selected tabs, which allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

Scores

CVSS v3 6.5
EPSS 0.0060
EPSS Percentile 69.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Classification

Status published

Affected Products (2)

google/chrome < 55.0.2883.87
n/a/Google Chrome prior to 56.0.2924.76 for Linux < Google Chrome prior to 56.0.2924.76 for Linux

Timeline

Published Feb 17, 2017
Tracked Since Feb 18, 2026