Timing Attack Vulnerability in Google Chrome's SVG Filters
CVE-2016-5224
Key Information:
- Vendor
Google
- Vendor
- CVE Published:
- 19 January 2017
What is CVE-2016-5224?
A vulnerability in Google Chrome's implementation of SVG filters allows a remote attacker to exploit a timing attack associated with denormalized floating point arithmetic. This flaw can be triggered via a specially crafted HTML page, enabling the attacker to bypass the Same Origin Policy, thereby potentially compromising the security of web applications and user data across different origins. Users of affected versions should update their browsers promptly to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved