CVE-2017-5022: Medium severity Google Chrome vulnerability
Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, failed to properly enforce unsafe-inline content security policy, which allowed a remote attacker to bypass content security policy via a crafted HTML page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5022?
CVE-2017-5022 is considered a high-severity vulnerability due to its potential for exploitation through unsafe-inline content security policies.
How do I fix CVE-2017-5022?
To fix CVE-2017-5022, upgrade to Google Chrome version 56.0.2924.76 or later for Linux, Windows, and Mac, or 56.0.2924.87 for Android.
What type of systems are affected by CVE-2017-5022?
CVE-2017-5022 affects Google Chrome versions prior to 56.0.2924.76 on Linux, Windows, Mac, and versions prior to 56.0.2924.87 on Android.
What can an attacker achieve with CVE-2017-5022?
An attacker can bypass the content security policy and execute malicious scripts by using a crafted HTML page.
Is there a workaround for CVE-2017-5022?
There are no effective workarounds for CVE-2017-5022 other than applying the necessary software updates.