CVE-2016-5201Sensitive Information Exposure in Google Chrome

Severity
6.5MEDIUMNVD
EPSS
0.5%
top 33.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 19
Latest updateMay 14

Description

A leak of privateClass in the extensions API in Google Chrome prior to 54.0.2840.100 for Linux, and 54.0.2840.99 for Windows, and 54.0.2840.98 for Mac allowed a remote attacker to access privileged JavaScript code via a crafted HTML page.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages1 packages

NVDgoogle/chrome54.0.2840.87

🔴Vulnerability Details

2
GHSA
GHSA-6jw7-vq8x-9cjf: A leak of privateClass in the extensions API in Google Chrome prior to 542022-05-14
OSV
CVE-2016-5201: A leak of privateClass in the extensions API in Google Chrome prior to 542017-01-19

📋Vendor Advisories

1
Red Hat
chromium-browser: info leak in extensions2016-11-09

💬Community

2
Bugzilla
CVE-2016-5201 chromium-browser: info leak in extensions2016-11-10
Bugzilla
CVE-2016-5199 CVE-2016-5200 CVE-2016-5201 CVE-2016-5202 chromium: various flaws [fedora-all]2016-11-10