First published: Fri Feb 17 2017(Updated: )
Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, failed to properly enforce unsafe-inline content security policy, which allowed a remote attacker to bypass content security policy via a crafted HTML page.
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome | <=55.0.2883.87 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-5022 is considered a high-severity vulnerability due to its potential for exploitation through unsafe-inline content security policies.
To fix CVE-2017-5022, upgrade to Google Chrome version 56.0.2924.76 or later for Linux, Windows, and Mac, or 56.0.2924.87 for Android.
CVE-2017-5022 affects Google Chrome versions prior to 56.0.2924.76 on Linux, Windows, Mac, and versions prior to 56.0.2924.87 on Android.
An attacker can bypass the content security policy and execute malicious scripts by using a crafted HTML page.
There are no effective workarounds for CVE-2017-5022 other than applying the necessary software updates.