Junglewise Threat Intelligence

CVE-2016-5215: Google Chrome use after free in WebAudio

CVE-2016-5215 · Severity: medium · CVSS 6.3 · Published 2017-01-19

Technologies: Google Chromium, Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a popular web browser used to access the internet. A vulnerability in its audio processing component could allow a malicious website to read information from the computer's memory that it should not have access to. This could lead to the exposure of sensitive data or cause the browser to crash if a user visits a specially crafted web page.

Technical details

A use-after-free (UAF) vulnerability exists in the WebAudio implementation of Google Chrome and Chromium. The flaw is triggered when the browser incorrectly manages memory objects during audio processing, allowing a remote attacker to induce an out-of-bounds (OOB) memory read. To exploit this, an attacker must entice a user to visit a specially crafted HTML page. Successful exploitation can result in the disclosure of sensitive information from the browser's memory space or a denial-of-service (crash) condition. The issue was resolved in Chrome version 55.0.2883.75 for desktop platforms and 55.0.2883.84 for Android.

Affected products

  • Google Chrome Prior to 55.0.2883.75 (Desktop); Prior to 55.0.2883.84 (Android)
  • Google Chromium Prior to 55.0.2883.75

Timeline

  • 2016-12-01: patched: Chrome Stable Channel Update for Desktop released
  • 2016-12-05: advisory: Gentoo Linux security advisory published
  • 2016-12-07: advisory: Red Hat security advisory published
  • 2017-01-19: disclosed: NVD publication date

References

Related threats