CVE-2016-5224: Medium severity Google Chrome vulnerability
A timing attack on denormalized floating point arithmetic in SVG filters in Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to bypass the Same Origin Policy via a crafted HTML page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5224?
CVE-2016-5224 is classified as a high severity vulnerability due to its potential to bypass the Same Origin Policy.
How do I fix CVE-2016-5224?
To fix CVE-2016-5224, update Google Chrome to version 55.0.2883.75 or later.
What impact does CVE-2016-5224 have on users?
CVE-2016-5224 allows remote attackers to execute a timing attack on floating point arithmetic, potentially compromising the security of users' data.
Is CVE-2016-5224 exploitable remotely?
Yes, CVE-2016-5224 can be exploited remotely via a crafted HTML page.
Which versions of Google Chrome are affected by CVE-2016-5224?
CVE-2016-5224 affects Google Chrome versions prior to 55.0.2883.75 on Mac, Windows, and Linux, and prior to 55.0.2883.84 on Android.