SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-5007

Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, incorrectly handled the sequence of events when closing a page, which allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a…

MEDIUM 6.1EPSS 2.25%

Does this matter?

Lower severity and a low EPSS score (2.25%). Track it; it rarely justifies an emergency change on its own.

Description

Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, incorrectly handled the sequence of events when closing a page, which allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.

CVSS 3.0
6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
2.25% probability · 82th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
google/chrome
Source
chrome-cve-admin@google.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.