SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2016-5207

In Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android, corruption of the DOM tree could occur during the removal of a full screen element, which allowed a remote attacker to achieve arbitrary code…

MEDIUM 6.1EPSS 1.99%

Does this matter?

Lower severity and a low EPSS score (1.99%). Track it; it rarely justifies an emergency change on its own.

Description

In Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android, corruption of the DOM tree could occur during the removal of a full screen element, which allowed a remote attacker to achieve arbitrary code execution via a crafted HTML page.

CVSS 3.0
6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
1.99% probability · 80th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
google/chrome
Source
chrome-cve-admin@google.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.