CVE-2017-5011: Infoleak
Google Chrome prior to 56.0.2924.76 for Windows insufficiently sanitized DevTools URLs, which allowed a remote attacker who convinced a user to install a malicious extension to read filesystem contents via a crafted HTML page.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Google Chrome for Windowsto a version that resolves this vulnerability.Fixed in 56.0.2924.76
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5011?
CVE-2017-5011 is classified as a high severity vulnerability due to its potential to allow remote attackers to read filesystem contents.
How do I fix CVE-2017-5011?
To fix CVE-2017-5011, upgrade Google Chrome to version 56.0.2924.76 or later.
What are the potential impacts of CVE-2017-5011?
The impact of CVE-2017-5011 includes unauthorized access to filesystem data if a malicious extension is installed.
Who is affected by CVE-2017-5011?
Users of Google Chrome versions prior to 56.0.2924.76 on Windows are affected by CVE-2017-5011.
Is CVE-2017-5011 a local or remote vulnerability?
CVE-2017-5011 is a remote vulnerability that requires user interaction for exploitation.