CVE-2016-5198: Google Chromium V8 Out-of-Bounds Memory Vulnerability
Google Chromium V8 Engine contains an out-of-bounds memory access vulnerability that allows a remote attacker to perform read/write operations, leading to code execution, via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Other sources
V8 in Google Chrome prior to 54.0.2840.90 for Linux, and 54.0.2840.85 for Android, and 54.0.2840.87 for Windows and Mac included incorrect optimisation assumptions, which allowed a remote attacker to perform arbitrary read/write operations, leading to code execution, via a crafted HTML page.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Google Chrome (Trace Event)to a version that resolves this vulnerability.Fixed in 54.0.2840.87
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5198?
CVE-2016-5198 has a high severity rating due to its potential for remote code execution through crafted HTML pages.
How do I fix CVE-2016-5198?
To fix CVE-2016-5198, update Google Chrome to version 54.0.2840.87 or later.
What software is affected by CVE-2016-5198?
CVE-2016-5198 affects various versions of Google Chrome prior to 54.0.2840.87 and Chromium V8 Engine.
Can CVE-2016-5198 be exploited remotely?
Yes, CVE-2016-5198 can be exploited remotely via a specially crafted HTML page.
Is there a workaround for CVE-2016-5198?
There is no official workaround for CVE-2016-5198; the recommended action is to upgrade to a secure version.