Junglewise Threat Intelligence

CVE-2016-5214: Google Chrome Mark of the Web bypass in file downloads

CVE-2016-5214 · Severity: medium · CVSS 4.3 · Published 2017-01-19

Technologies: Google Chrome, Google Chromium. Vendors: Google.

Executive brief

Google Chrome for Windows contained a flaw that allowed downloaded files to bypass a security feature known as 'Mark of the Web.' This feature is used by the operating system to identify files from the internet and trigger security warnings before they are opened. An attacker could use a malicious website to trick a user into downloading a file that would then appear to be from a trusted local source, potentially leading to the execution of harmful software without the usual security prompts.

Technical details

A vulnerability in Google Chrome prior to 55.0.2883.75 for Windows allowed a remote attacker to prevent downloaded files from receiving the 'Mark of the Web' (MotW) NTFS alternate data stream. By using a crafted HTML page, an attacker could trigger a download that bypasses this security zone identifier. This bypass is significant because Windows and other applications use the MotW to apply restrictive security policies, such as Protected View in Office or 'Open File - Security Warning' prompts. The vulnerability is categorized under CWE-19 (Data Processing Errors) and requires user interaction to visit a malicious site and initiate a download. The issue was resolved in version 55.0.2883.75.

Affected products

  • Google Chrome < 55.0.2883.75
  • Google Chromium < 55.0.2883.75

Timeline

  • 2016-12-01: patched: Chrome 55.0.2883.75 released to stable channel
  • 2017-01-19: disclosed: NVD publication date

References

Related threats