First published: Thu Dec 01 2016(Updated: )
Blink in Google Chrome prior to 55.0.2883.75 for Linux, Windows and Mac executed javascript: URLs entered in the URL bar in the context of the current tab, which allowed a socially engineered user to XSS themselves by dragging and dropping a javascript: URL into the URL bar.
Credit: cve-coordination@google.com chrome-cve-admin@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome (Trace Event) | <55.0.2883.75 | 55.0.2883.75 |
Google Chrome (Trace Event) | <=54.0.2840.99 | |
Google Chrome | <=54.0.2840.99 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2016-5226 has a severity level categorized as medium due to its exploitation potential through social engineering.
To fix CVE-2016-5226, upgrade Google Chrome to version 55.0.2883.75 or later.
CVE-2016-5226 is an XSS vulnerability that allows for self-inflicted attacks via manipulated javascript: URLs.
CVE-2016-5226 affects Google Chrome versions prior to 55.0.2883.75 on Linux, Windows, and Mac.
CVE-2016-5226 cannot be exploited remotely as it requires user interaction to inject the malicious javascript: URL.