Use After Free Vulnerability in PDFium for Google Chrome
CVE-2016-5203
8.8HIGH
Key Information:
- Vendor
Google
- Vendor
- CVE Published:
- 19 January 2017
What is CVE-2016-5203?
A use after free vulnerability in the PDFium component of Google Chrome can be exploited by attackers through a specially crafted PDF file. This flaw, present in versions prior to 55.0.2883.75 for Mac, Windows, and Linux, and prior to 55.0.2883.84 for Android, can lead to heap corruption, potentially allowing a remote attacker to execute arbitrary code. Users are advised to update their browsers to mitigate these risks.
Affected Version(s)
Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android