CVE-2017-5016
Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, failed to prevent certain UI elements from being displayed by non-visible pages, which allowed a remote attacker to show certain UI elements on a page…
Does this matter?
Lower severity and a low EPSS score (1.29%). Track it; it rarely justifies an emergency change on its own.
Description
Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, failed to prevent certain UI elements from being displayed by non-visible pages, which allowed a remote attacker to show certain UI elements on a page they don't control via a crafted HTML page.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
- EPSS
- 1.29% probability · 69th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-1021
- Affected
- google/chrome
- Source
- chrome-cve-admin@google.com
References
- http://rhn.redhat.com/errata/RHSA-2017-0206.html
- http://www.debian.org/security/2017/dsa-3776
- http://www.securityfocus.com/bid/95792
- http://www.securitytracker.com/id/1037718
- https://chromereleases.googleblog.com/2017/01/stable-channel-update-for-desktop.html
- https://crbug.com/673163
- https://security.gentoo.org/glsa/201701-66
- http://rhn.redhat.com/errata/RHSA-2017-0206.html
- http://www.debian.org/security/2017/dsa-3776
- http://www.securityfocus.com/bid/95792
- http://www.securitytracker.com/id/1037718
- https://chromereleases.googleblog.com/2017/01/stable-channel-update-for-desktop.html
- https://crbug.com/673163
- https://security.gentoo.org/glsa/201701-66
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.