XSS Vulnerability in Google Chrome for Windows, Linux, and Mac
CVE-2016-5226

6.1MEDIUM

Key Information:

Vendor
Google
Vendor
CVE Published:
19 January 2017

Summary

The vulnerability allows a user to execute arbitrary JavaScript code by dragging and dropping a malicious 'javascript:' URL into the Google Chrome URL bar. This risks exposing sensitive information and could lead to various security exploits as the script executes within the context of the current tab. Users are encouraged to update Google Chrome to the latest version to mitigate this potential risk.

Affected Version(s)

Google Chrome prior to 55.0.2883.75 for Linux, Windows and Mac Google Chrome prior to 55.0.2883.75 for Linux, Windows and Mac

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.