Junglewise Threat Intelligence

CVE-2016-5211: Google Chrome use after free in PDFium

CVE-2016-5211 · Severity: high · CVSS 8.8 · Published 2017-01-19

Technologies: Google Chromium, Google Chrome. Vendors: Google.

Executive brief

Google Chrome's PDF viewer (PDFium) contains a vulnerability that can be triggered when a user opens a specially crafted PDF file. This flaw could allow an attacker to crash the browser or potentially execute unauthorized commands on the user's computer. Successful exploitation could lead to the theft of sensitive data or a complete compromise of the user's browsing session.

Technical details

A use-after-free (UAF) vulnerability exists in PDFium, the default PDF engine in Google Chrome and Chromium-based browsers. The flaw is triggered during the processing of malformed PDF content, leading to heap corruption. A remote attacker can exploit this by enticing a user to open a specially crafted PDF file or visit a website hosting such a file. If successfully exploited, the attacker could achieve arbitrary code execution within the context of the browser's sandbox or cause a denial-of-service (DoS) condition. The vulnerability was addressed in Chrome version 55.0.2883.75 for desktop platforms and 55.0.2883.84 for Android.

Affected products

  • Google Chrome Prior to 55.0.2883.75 (Desktop); Prior to 55.0.2883.84 (Android)
  • Google Chromium Prior to 55.0.2883.75

Timeline

  • 2016-12-01: patched: Chrome Stable Channel update 55.0.2883.75 released for Desktop
  • 2016-12-05: advisory: Gentoo GLSA 201612-11 published
  • 2016-12-07: advisory: Red Hat RHSA-2016:2919 published
  • 2017-01-19: disclosed: NVD publication date

References

Related threats