First published: Tue Nov 01 2016(Updated: )
Google Chromium V8 Engine contains an out-of-bounds memory access vulnerability that allows a remote attacker to perform read/write operations, leading to code execution, via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Credit: cve-coordination@google.com chrome-cve-admin@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google V8 | ||
Google Chrome (Trace Event) | <54.0.2840.87 | 54.0.2840.87 |
All of | ||
Google Chrome (Trace Event) | <54.0.2840.90 | |
Linux Kernel | ||
All of | ||
Google Chrome (Trace Event) | <54.0.2840.85 | |
Android | ||
All of | ||
Google Chrome (Trace Event) | <54.0.2840.87 | |
Any of | ||
Apple iOS and macOS | ||
Microsoft Windows | ||
Red Hat Enterprise Linux Desktop | =6.0 | |
Red Hat Enterprise Linux Server | =6.0 | |
Red Hat Enterprise Linux Workstation | =6.0 | |
Google Chrome (Trace Event) | <=54.0.2840.71 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-5198 has a high severity rating due to its potential for remote code execution through crafted HTML pages.
To fix CVE-2016-5198, update Google Chrome to version 54.0.2840.87 or later.
CVE-2016-5198 affects various versions of Google Chrome prior to 54.0.2840.87 and Chromium V8 Engine.
Yes, CVE-2016-5198 can be exploited remotely via a specially crafted HTML page.
There is no official workaround for CVE-2016-5198; the recommended action is to upgrade to a secure version.