Junglewise Threat Intelligence

CVE-2016-5204: Google Chrome Universal XSS in Blink SVG shadow tree

CVE-2016-5204 · Severity: medium · CVSS 6.1 · Published 2017-01-19

Technologies: Google Chromium, Google Chrome. Vendors: Google.

Executive brief

A vulnerability in the Google Chrome web browser allowed malicious websites to bypass security boundaries. By tricking a user into visiting a specially crafted web page, an attacker could inject unauthorized scripts or HTML into other websites the user is visiting. This could lead to the theft of sensitive information or unauthorized actions performed on the user's behalf.

Technical details

A Universal Cross-Site Scripting (UXSS) vulnerability exists in the Blink rendering engine of Google Chrome due to the leaking of an SVG shadow tree, which leads to corruption of the Document Object Model (DOM) tree. By leveraging a crafted HTML page, a remote attacker can bypass the Same-Origin Policy (SOP) to execute arbitrary JavaScript in the context of any website. This issue affected Chrome versions prior to 55.0.2883.75 on desktop platforms and 55.0.2883.84 on Android. The vulnerability is triggered when a user visits a malicious site, requiring no special privileges from the attacker.

Affected products

  • Google Chrome < 55.0.2883.75 (Desktop); < 55.0.2883.84 (Android)
  • Google Chromium < 55.0.2883.75

Timeline

  • 2016-12-01: patched: Chrome 55.0.2883.75 released for desktop
  • 2016-12-05: advisory: Gentoo GLSA 201612-11 published
  • 2016-12-07: advisory: Red Hat RHSA-2016:2919 published
  • 2017-01-19: disclosed: NVD publication date

References

Related threats