Use After Free Flaw in PDFium Affects Google Chrome
CVE-2016-5216
6.3MEDIUM
Key Information:
- Vendor
- Vendor
- CVE Published:
- 19 January 2017
Summary
A use after free vulnerability in the PDFium library used by Google Chrome can lead to remote code execution through specially crafted PDF documents. This flaw can allow attackers to exploit out of bounds memory reads, potentially leading to unauthorized access and data manipulation. Users are advised to update to the latest versions to mitigate risks associated with this security issue.
Affected Version(s)
Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android
References
CVSS V3.1
Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved