Junglewise Threat Intelligence

CVE-2016-5220: Google Chrome local file disclosure in PDFium

CVE-2016-5220 · Severity: medium · CVSS 6.5 · Published 2017-01-19

Technologies: Google Chromium, Google Chrome. Vendors: Google.

Executive brief

Google Chrome's PDF viewer, PDFium, contained a flaw in how it handled navigation within PDF documents. An attacker could exploit this by tricking a user into opening a specially crafted PDF file, which would then allow the attacker to access and read private files stored on the user's computer or device. This could lead to the theft of sensitive personal information or corporate data.

Technical details

An information disclosure vulnerability existed in PDFium, the PDF engine used in Google Chrome and Chromium-based browsers. The flaw was rooted in the incorrect handling of navigation events within PDF documents. By enticing a user to open a maliciously crafted PDF, a remote attacker could bypass security boundaries to access and read arbitrary local files on the host system. This vulnerability is classified under CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). The issue was resolved in Chrome version 55.0.2883.75 for desktop platforms and 55.0.2883.84 for Android.

Affected products

  • Google Chrome < 55.0.2883.75 (Desktop); < 55.0.2883.84 (Android)
  • Google Chromium < 55.0.2883.75

Timeline

  • 2016-12-01: advisory: Google released Chrome 55.0.2883.75 with security fixes
  • 2016-12-05: advisory: Gentoo released GLSA 201612-11
  • 2016-12-07: patched: Red Hat released security update RHSA-2016:2919
  • 2017-01-19: disclosed: NVD publication date

References

Related threats