Junglewise Threat Intelligence

CVE-2016-5203: Google Chrome use after free in PDFium

CVE-2016-5203 · Severity: high · CVSS 8.8 · Published 2017-01-19

Technologies: Google Chromium, Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in the PDF viewing component of the Google Chrome web browser. By tricking a user into opening a specially crafted PDF file, a remote attacker could potentially crash the browser or execute unauthorized code on the user's device. This could lead to the theft of sensitive data or a complete compromise of the affected system.

Technical details

A use-after-free (UAF) vulnerability exists in PDFium, the PDF rendering engine used in Google Chrome and Chromium. The flaw is triggered when the engine incorrectly manages memory during the processing of a malformed PDF document. A remote attacker can exploit this by hosting a malicious PDF file and enticing a user to view it, leading to heap corruption. Successful exploitation could allow for arbitrary code execution within the context of the browser's sandbox or a denial-of-service (browser crash). The issue was resolved in Chrome version 55.0.2883.75 for desktop platforms and 55.0.2883.84 for Android.

Affected products

  • Google Chrome prior to 55.0.2883.75 (Desktop); prior to 55.0.2883.84 (Android)
  • Google Chromium prior to 55.0.2883.75

Timeline

  • 2016-12-01: patched: Chrome Stable Channel Update for Desktop released
  • 2016-12-05: advisory: Gentoo Linux security advisory published
  • 2016-12-07: advisory: Red Hat security advisory published
  • 2017-01-19: disclosed: NVD publication date

References

Related threats