CVE-2016-5196
published 2017-01-19CVE-2016-5196: The content renderer client in Google Chrome prior to 54.0.2840.85 for Android insufficiently enforced the Same Origin Policy amongst downloaded files, which…
PriorityP341high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
0.98%
58.8th percentile
The content renderer client in Google Chrome prior to 54.0.2840.85 for Android insufficiently enforced the Same Origin Policy amongst downloaded files, which allowed a remote attacker to access any downloaded file and interact with sites, including those the user was logged into, via a crafted HTML page.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | <= 54.0.2840.68 | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Chrome up to 54 on Android Content Renderer Client 7pk security (BID-94078)
vuldb·2026-05-14·CVSS 8.8
CVE-2016-5196 [HIGH] Google Chrome up to 54 on Android Content Renderer Client 7pk security (BID-94078)
A vulnerability marked as critical has been reported in Google Chrome up to 54 on Android. This affects an unknown function of the component Content Renderer Client. The manipulation leads to 7pk security features.
This vulnerability is uniquely identified as CVE-2016-5196. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.
GHSA
GHSA-qj3x-4qq5-763f: The content renderer client in Google Chrome prior to 54
ghsa_unreviewed·2022-05-17
CVE-2016-5196 [HIGH] GHSA-qj3x-4qq5-763f: The content renderer client in Google Chrome prior to 54
The content renderer client in Google Chrome prior to 54.0.2840.85 for Android insufficiently enforced the Same Origin Policy amongst downloaded files, which allowed a remote attacker to access any downloaded file and interact with sites, including those the user was logged into, via a crafted HTML page.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-01-19
Published