Out-of-Bounds Memory Read in Google Chrome Affecting Multiple Platforms
CVE-2016-5186

5.3MEDIUM

What is CVE-2016-5186?

A flaw in Google Chrome's DevTools prior to specified versions permitted an out-of-bounds memory read after a tab crash. This vulnerability could be exploited by a remote attacker by deploying specially crafted PDF files, potentially leading to unauthorized information disclosure. Available updates contain patches to mitigate this risk.

Affected Version(s)

Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.