Type Confusion Vulnerability in ANGLE Product by Google
CVE-2016-5221

6.3MEDIUM

Summary

A type confusion vulnerability exists in the ANGLE component of Google Chrome, which could be exploited by attackers through the use of specially crafted HTML pages. This flaw affects various versions of Google Chrome across multiple platforms, including Mac, Windows, Linux, and Android. Successful exploitation may allow an attacker to bypass buffer validation, potentially leading to unauthorized actions within the browser environment.

Affected Version(s)

Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.