DOM Tree Corruption Vulnerability in Google Chrome on Multiple Platforms
CVE-2016-5207
6.1MEDIUM
Key Information:
- Vendor
- Vendor
- CVE Published:
- 19 January 2017
Summary
A vulnerability in Blink, the rendering engine for Google Chrome, can lead to DOM tree corruption when a full-screen element is removed. This issue affects versions of Google Chrome prior to 55.0.2883.75 on Mac, Windows, Linux, and 55.0.2883.84 on Android. By exploiting this vulnerability, a remote attacker could potentially execute arbitrary code through a specially crafted HTML page, highlighting serious implications for users' security.
Affected Version(s)
Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved