CVE-2016-5187Improper Input Validation in Google Chrome

Severity
6.5MEDIUMNVD
OSV7.5
EPSS
0.4%
top 40.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 18
Latest updateMay 14

Description

Google Chrome prior to 54.0.2840.85 for Android incorrectly handled rapid transition into and out of full screen mode, which allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via crafted HTML pages.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages1 packages

NVDgoogle/chrome53.0.2785.143

🔴Vulnerability Details

3
GHSA
GHSA-52jh-hj3q-x9m5: Google Chrome prior to 542022-05-14
OSV
oxide-qt vulnerabilities2016-11-02
OSV
CVE-2016-5187: Google Chrome prior to 542016-10-17

📋Vendor Advisories

2
Ubuntu
Oxide vulnerabilities2016-11-02
Red Hat
chromium-browser: url spoofing2016-10-12

💬Community

2
Bugzilla
CVE-2016-5187 chromium-browser: url spoofing2016-10-13
Bugzilla
CVE-2016-5181 CVE-2016-5182 CVE-2016-5183 CVE-2016-5184 CVE-2016-5185 CVE-2016-5186 CVE-2016-5187 CVE-2016-5188 CVE-2016-5189 CVE-2016-5190 CVE-2016-5191 CVE-2016-5192 CVE-2016-5193 CVE-2016-5194 chro2016-10-13