Timing Attack Vulnerability in Google Chrome's SVG Filters
CVE-2016-5224
4.3MEDIUM
Key Information:
- Vendor
- Vendor
- CVE Published:
- 19 January 2017
Summary
A vulnerability in Google Chrome's implementation of SVG filters allows a remote attacker to exploit a timing attack associated with denormalized floating point arithmetic. This flaw can be triggered via a specially crafted HTML page, enabling the attacker to bypass the Same Origin Policy, thereby potentially compromising the security of web applications and user data across different origins. Users of affected versions should update their browsers promptly to mitigate this risk.
Affected Version(s)
Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved