Junglewise Threat Intelligence

CVE-2016-5200: Google Chrome V8 out of bounds memory access

CVE-2016-5200 · Severity: high · CVSS 8.8 · Published 2017-01-19

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in the Google Chrome web browser could allow a remote attacker to compromise a user's computer. By tricking a user into visiting a specially crafted website, an attacker could cause the browser to crash or potentially execute malicious code. This could lead to the theft of sensitive personal data or unauthorized access to the user's system.

Technical details

A heap-based memory corruption vulnerability exists in the V8 JavaScript engine used by Google Chrome. The flaw is caused by the incorrect application of type rules during code execution. A remote attacker can exploit this by enticing a user to visit a maliciously crafted HTML page. Successful exploitation can lead to out-of-bounds memory access, potentially allowing for arbitrary code execution within the context of the browser process. Google has addressed this issue in Chrome versions 54.0.2840.98 (Mac), 54.0.2840.99 (Windows), 54.0.2840.100 (Linux), and 55.0.2883.84 (Android).

Affected products

  • Google Chrome prior to 54.0.2840.98 (Mac), 54.0.2840.99 (Windows), 54.0.2840.100 (Linux), 55.0.2883.84 (Android)

Timeline

  • 2016-11-09: patched: Stable channel update released for desktop platforms.
  • 2016-11-22: advisory: Gentoo Linux security advisory published.
  • 2017-01-19: disclosed: NVD publication date.

References

Related threats