Timing Attack in SVG Rendering of Google Chrome
CVE-2017-5107
Key Information:
- Vendor
Google
- Vendor
- CVE Published:
- 27 October 2017
What is CVE-2017-5107?
A timing attack vulnerability was discovered in the SVG rendering process of Google Chrome that affects multiple platforms, including Linux, Windows, and Mac. This vulnerability enables remote attackers to exploit a flaw when a page is rendered within an iframe on a cross-origin site, potentially allowing them to extract pixel values from the rendered content. Such an attack can compromise the confidentiality of user data and content across sites.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Google Chrome prior to 60.0.3112.78 for Linux, Windows and Mac Google Chrome prior to 60.0.3112.78 for Linux, Windows and Mac
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved