CVE-2016-5197: Input Validation
The content view client in Google Chrome prior to 54.0.2840.85 for Android insufficiently validated intent URLs, which allowed a remote attacker who had compromised the renderer process to start arbitrary activity on the system via a crafted HTML page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5197?
CVE-2016-5197 has a high severity rating due to its potential to allow arbitrary activity on the system through crafted HTML pages.
How do I fix CVE-2016-5197?
To fix CVE-2016-5197, update Google Chrome for Android to version 54.0.2840.85 or later.
What versions of Google Chrome are affected by CVE-2016-5197?
CVE-2016-5197 affects all versions of Google Chrome for Android prior to 54.0.2840.85.
Can CVE-2016-5197 affect other software besides Google Chrome?
CVE-2016-5197 specifically targets the Google Chrome browser on Android devices and does not affect other software.
What type of attack is associated with CVE-2016-5197?
CVE-2016-5197 allows remote attackers to exploit the vulnerability by leveraging a compromised renderer process to execute arbitrary actions.