CVE-2017-5016

MEDIUM

Google Chrome <56.0.2924.76-56.0.2924.87 - Info Disclosure

Title source: llm
STIX 2.1

Description

Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, failed to prevent certain UI elements from being displayed by non-visible pages, which allowed a remote attacker to show certain UI elements on a page they don't control via a crafted HTML page.

References (7)

Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/95792
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/201701-66
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2017-0206.html
Issue Tracking x_refsource_confirm
https://crbug.com/673163
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1037718
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2017/dsa-3776

Scores

CVSS v3 6.5
EPSS 0.0129
EPSS Percentile 66.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Details

CWE
CWE-1021
Status published
Products (2)
google/chrome < 55.0.2883.87
n/a/Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android
Published Feb 17, 2017
Tracked Since Feb 18, 2026