Executive brief
A vulnerability in Google Chrome's web rendering engine could allow an attacker to compromise a user's computer if they visit a malicious website. This issue stems from how the browser handles images and could lead to a complete system takeover or the theft of sensitive data. Users are protected by updating to the latest version of the browser.
Technical details
A bad casting vulnerability exists in the bitmap manipulation component of the Blink rendering engine (part of Chromium/Google Chrome). The flaw is triggered when the browser processes specially crafted HTML content, leading to an out-of-bounds write (CWE-787) and subsequent heap corruption. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious webpage. Successful exploitation could result in arbitrary code execution within the context of the browser process. The issue was addressed in Chrome version 55.0.2883.75 for desktop and 55.0.2883.84 for Android.
Affected products
- Google Chrome prior to 55.0.2883.75
- Google Chrome for Android prior to 55.0.2883.84
- Google Chromium prior to 55.0.2883.75
Timeline
- 2016-12-01: patched: Chrome Stable Channel Update for Desktop released
- 2016-12-05: advisory: Gentoo Linux security advisory published
- 2016-12-07: advisory: Red Hat security advisory published
- 2017-01-19: disclosed: NVD publication date