Junglewise Threat Intelligence

CVE-2016-5205: Google Chrome UXSS in Blink via deferred page loads

CVE-2016-5205 · Severity: medium · CVSS 6.1 · Published 2017-01-19

Technologies: Google Chrome, Google Chromium. Vendors: Google.

Executive brief

Google Chrome is a popular web browser used to access the internet. A vulnerability in its rendering engine could allow a malicious website to run unauthorized scripts in the context of other websites you have open. This could lead to the theft of sensitive information, such as login credentials or personal data, from those other sites.

Technical details

A Universal Cross-Site Scripting (UXSS) vulnerability exists in the Blink rendering engine of Google Chrome. The flaw is caused by the incorrect handling of deferred page loads, which can be exploited by a remote attacker who entices a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to bypass the Same-Origin Policy (SOP) and inject arbitrary scripts or HTML into any web page. This vulnerability was addressed in Chrome version 55.0.2883.75.

Affected products

  • Google Chrome prior to 55.0.2883.75
  • Google Chromium prior to 55.0.2883.75

Timeline

  • 2016-12-01: patched: Chrome 55.0.2883.75 released to stable channel
  • 2017-01-19: disclosed: NVD publication date

References

Related threats