CVE-2016-5217: Medium severity Google Chrome vulnerability
The extensions API in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android incorrectly permitted access to privileged plugins, which allowed a remote attacker to bypass site isolation via a crafted HTML page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5217?
CVE-2016-5217 has a medium severity rating as it allows remote attackers to bypass site isolation.
How do I fix CVE-2016-5217?
To fix CVE-2016-5217, upgrade Google Chrome to version 55.0.2883.75 or later.
Which versions of Google Chrome are affected by CVE-2016-5217?
CVE-2016-5217 affects Google Chrome versions prior to 55.0.2883.75 on Mac, Windows, and Linux, and versions prior to 55.0.2883.84 on Android.
What does CVE-2016-5217 allow an attacker to do?
CVE-2016-5217 allows attackers to exploit privileged plugins via a crafted HTML page.
Where can I find more information about CVE-2016-5217?
For more details about CVE-2016-5217, refer to official security advisories and update notes from Google.