CVE-2017-5118

MEDIUM

Google Chrome <61.0.3163.79-61.0.3163.81 - XSS

Title source: llm
STIX 2.1

Description

Blink in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.3163.81 for Android, failed to correctly propagate CSP restrictions to javascript scheme pages, which allowed a remote attacker to bypass content security policy via a crafted HTML page.

References (7)

Core 7
Core References
Issue Tracking x_refsource_misc
https://crbug.com/747847
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/201709-15
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:2676
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1039291
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/100610
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2017/dsa-3985

Scores

CVSS v3 4.3
EPSS 0.0033
EPSS Percentile 55.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Details

CWE
CWE-732
Status published
Products (7)
debian/debian_linux 9.0
debian/debian_linux 10.0
google/chrome < 61.0.3163.79
n/a/Google Chrome prior to 61.0.3163.79 for Mac, Windows and Linux, and 61.0.3163.81 for Android Google Chrome prior to 61.0.3163.79 for Mac, Windows and Linux, and 61.0.3163.81 for Android
redhat/enterprise_linux_desktop 6.0
redhat/enterprise_linux_server 6.0
redhat/enterprise_linux_workstation 6.0
Published Oct 27, 2017
Tracked Since Feb 18, 2026