Junglewise Threat Intelligence

CVE-2016-5212: Google Chrome local file disclosure in DevTools

CVE-2016-5212 · Severity: medium · CVSS 6.5 · Published 2017-01-19

Technologies: Google Chrome, Google Chromium. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's developer tools could allow a malicious website to access files stored locally on a user's computer. This occurs when a user visits a specially crafted web page, potentially leading to the theft of sensitive personal or corporate data. The issue affects Chrome on Windows, Mac, Linux, and Android devices.

Technical details

A local file disclosure vulnerability exists in Google Chrome's DevTools component due to insufficient sanitization of DevTools URLs. An attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the remote attacker to bypass security restrictions and read arbitrary local files on the victim's system. The vulnerability is categorized as an information exposure (CWE-200) and was addressed in Chrome version 55.0.2883.75 for desktop and 55.0.2883.84 for Android.

Affected products

  • Google Chrome prior to 55.0.2883.75 (Desktop); prior to 55.0.2883.84 (Android)
  • Google Chromium prior to 55.0.2883.75

Timeline

  • 2016-12-01: patched: Chrome 55.0.2883.75 released for desktop
  • 2016-12-05: advisory: Gentoo GLSA 201612-11 published
  • 2016-12-07: advisory: Red Hat RHSA-2016:2919 published
  • 2017-01-19: disclosed: NVD publication date

References

Related threats