CVE-2017-15405: Race Condition
Inappropriate symlink handling and a race condition in the stateful recovery feature implementation could lead to a persistance established by a malicious code running with root privileges in cryptohomed in Google Chrome on Chrome OS prior to 61.0.3163.113 allowed a local attacker to execute arbitrary code via a crafted HTML page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-15405?
CVE-2017-15405 is classified as a high severity vulnerability due to its potential for remote code execution with root privileges.
How do I fix CVE-2017-15405?
To fix CVE-2017-15405, upgrade Google Chrome to version 61.0.3163.113 or later.
What type of vulnerability is CVE-2017-15405?
CVE-2017-15405 is an inappropriate symlink handling vulnerability combined with a race condition.
Who is affected by CVE-2017-15405?
CVE-2017-15405 affects users of Google Chrome on Chrome OS versions prior to 61.0.3163.113.
What could an attacker achieve with CVE-2017-15405?
An attacker could exploit CVE-2017-15405 to execute arbitrary code with root privileges on the affected systems.