CVE-2016-5196: orig in data accessCredit to Robert Miller and Georgi Geshev from MWR Labs, working with Trend Micro's Zero Day Initiative
The content renderer client in Google Chrome prior to 54.0.2840.85 for Android insufficiently enforced the Same Origin Policy amongst downloaded files, which allowed a remote attacker to access any downloaded file and interact with sites, including those the user was logged into, via a crafted HTML page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5196?
CVE-2016-5196 is rated as a high severity vulnerability due to its potential to allow remote attackers to access sensitive downloaded files.
How do I fix CVE-2016-5196?
To fix CVE-2016-5196, update Google Chrome to version 54.0.2840.85 or later on Android devices.
What versions of Chrome are affected by CVE-2016-5196?
CVE-2016-5196 affects all versions of Google Chrome prior to 54.0.2840.85 on Android.
What types of attacks can exploit CVE-2016-5196?
CVE-2016-5196 can be exploited by remote attackers to access any downloaded file and interact with web pages where the user is logged in.
Who is affected by CVE-2016-5196?
Users of Google Chrome on Android versions earlier than 54.0.2840.85 are affected by CVE-2016-5196.