First published: Thu Jan 19 2017(Updated: )
Google Chrome prior to 55.0.2883.75 for Windows mishandled downloaded files, which allowed a remote attacker to prevent the downloaded file from receiving the Mark of the Web via a crafted HTML page.
Credit: cve-coordination@google.com chrome-cve-admin@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome (Trace Event) | <=54.0.2840.99 | |
Google Chrome | <=54.0.2840.99 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-5214 has a medium severity rating, which indicates a potential risk to users of affected Google Chrome versions.
To fix CVE-2016-5214, you should update Google Chrome to version 55.0.2883.75 or later.
CVE-2016-5214 allows a remote attacker to prevent the Mark of the Web from being applied to downloaded files, which can lead to security issues.
CVE-2016-5214 affects Google Chrome versions prior to 55.0.2883.75 on Windows.
There are no specific workarounds for CVE-2016-5214 other than upgrading to the latest version of Google Chrome.