Timing Attack in SVG Rendering of Google Chrome
CVE-2017-5107
5.3MEDIUM
Key Information:
- Vendor
Google
- Vendor
- CVE Published:
- 27 October 2017
What is CVE-2017-5107?
A timing attack vulnerability was discovered in the SVG rendering process of Google Chrome that affects multiple platforms, including Linux, Windows, and Mac. This vulnerability enables remote attackers to exploit a flaw when a page is rendered within an iframe on a cross-origin site, potentially allowing them to extract pixel values from the rendered content. Such an attack can compromise the confidentiality of user data and content across sites.
Affected Version(s)
Google Chrome prior to 60.0.3112.78 for Linux, Windows and Mac Google Chrome prior to 60.0.3112.78 for Linux, Windows and Mac