CVE-2016-5225: Medium severity Google Chrome vulnerability
Published Jan 19, 2017
·Updated
Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android incorrectly handled form actions, which allowed a remote attacker to bypass Content Security Policy via a crafted HTML page.
Affected Software
1 affected component
Google Chrome<=54.0.2840.99
Event History
Jan 19, 2017
CVE Published
via MITRE·05:43 AM
Data Sourced
via MITRE·05:43 AM
DescriptionWeakness
Data Sourced
via NVD·05:59 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-5225?
CVE-2016-5225 is classified as a high severity vulnerability.
2
How do I fix CVE-2016-5225?
To fix CVE-2016-5225, update Google Chrome to version 55.0.2883.75 or later.
3
What systems are affected by CVE-2016-5225?
CVE-2016-5225 affects Google Chrome versions prior to 55.0.2883.75 on Mac, Windows, and Linux, as well as 55.0.2883.84 on Android.
4
What type of attack does CVE-2016-5225 allow?
CVE-2016-5225 allows a remote attacker to bypass the Content Security Policy via a crafted HTML page.
5
Is there a workaround for CVE-2016-5225?
There are no known workarounds for CVE-2016-5225; the best course of action is to upgrade Chrome.