First published: Thu Jan 19 2017(Updated: )
PDFium in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android incorrectly handled navigation within PDFs, which allowed a remote attacker to read local files via a crafted PDF file.
Credit: cve-coordination@google.com chrome-cve-admin@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome (Trace Event) | <=54.0.2840.99 | |
Google Chrome | <=54.0.2840.99 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-5220 has been assigned a high severity rating due to the potential for remote attackers to access local files.
To fix CVE-2016-5220, upgrade Google Chrome to version 55.0.2883.75 or later on your operating system.
The potential impacts of CVE-2016-5220 include unauthorized access to sensitive local files through crafted PDF files.
Google Chrome versions prior to 55.0.2883.75 for Mac, Windows, and Linux, and 55.0.2883.84 for Android are affected by CVE-2016-5220.
CVE-2016-5220 affects Google Chrome on multiple operating systems, including Mac, Windows, and Linux.