Junglewise Threat Intelligence

CVE-2016-5207: Google Chrome Universal XSS in Blink via DOM corruption

CVE-2016-5207 · Severity: medium · CVSS 6.1 · Published 2017-01-19

Technologies: Google Chrome, Google Chromium. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser for desktop and mobile devices. A vulnerability was found where visiting a malicious website could allow an attacker to corrupt the browser's internal representation of a web page. This could lead to unauthorized actions on other websites or, in some cases, the execution of malicious code on the user's device.

Technical details

A vulnerability exists in the Blink rendering engine of Google Chrome due to improper handling of the Document Object Model (DOM) tree when a full-screen element is removed. This flaw can lead to DOM tree corruption, which a remote attacker can exploit by enticing a user to visit a specially crafted HTML page. Successful exploitation can result in Universal Cross-Site Scripting (UXSS) or arbitrary code execution within the context of the browser process. The issue was addressed in Chrome version 55.0.2883.75 for desktop platforms and 55.0.2883.84 for Android.

Affected products

  • Google Chrome Prior to 55.0.2883.75 (Desktop); Prior to 55.0.2883.84 (Android)
  • Google Chromium Prior to 55.0.2883.75

Timeline

  • 2016-12-01: patched: Chrome 55.0.2883.75 released for desktop
  • 2016-12-05: advisory: Gentoo security advisory published
  • 2016-12-07: advisory: Red Hat security advisory published
  • 2017-01-19: disclosed: NVD publication date

References

Related threats