Timing Attack Vulnerability in Google Chrome's SVG Filters
CVE-2016-5224
4.3MEDIUM
Key Information:
- Vendor
Google
- Vendor
- CVE Published:
- 19 January 2017
What is CVE-2016-5224?
A vulnerability in Google Chrome's implementation of SVG filters allows a remote attacker to exploit a timing attack associated with denormalized floating point arithmetic. This flaw can be triggered via a specially crafted HTML page, enabling the attacker to bypass the Same Origin Policy, thereby potentially compromising the security of web applications and user data across different origins. Users of affected versions should update their browsers promptly to mitigate this risk.
Affected Version(s)
Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android