Junglewise Threat Intelligence

CVE-2016-5197: Google Chrome for Android improper intent validation

CVE-2016-5197 · Severity: high · CVSS 8.8 · Published 2017-01-19

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome for Android is a mobile web browser used to access the internet. A security flaw in how the browser handles specific web links (intents) could allow a malicious website to trigger unauthorized actions on a user's device. If exploited, an attacker could potentially launch other apps or perform system activities without the user's permission, compromising the device's security.

Technical details

An improper input validation vulnerability exists in the content view client of Google Chrome for Android prior to version 54.0.2840.85. The flaw stems from insufficient validation of 'intent://' scheme URLs. A remote attacker who has already compromised the renderer process can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to bypass security boundaries and launch arbitrary Android activities (app components) on the underlying system. This issue was addressed in the Chrome for Android update to version 54.0.2840.85.

Affected products

  • Google Chrome Prior to 54.0.2840.85

Timeline

  • 2016-10-31: patched: Chrome for Android version 54.0.2840.85 released
  • 2017-01-19: disclosed: NVD publication date

References

Related threats