CVE-2017-5027: Bypass of Content Security Policy in BlinkCredit to 李普君 of 无声信息技术PKAV Team
Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, failed to properly enforce unsafe-inline content security policy, which allowed a remote attacker to bypass content security policy via a crafted HTML page.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Google Chrome (Trace Event)to a version that resolves this vulnerability.Fixed in 56.0.2924.76
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2017-5027?
CVE-2017-5027 has a high severity rating due to its potential for allowing remote attackers to bypass content security policy.
How do I fix CVE-2017-5027?
To fix CVE-2017-5027, it is recommended to update Google Chrome to version 56.0.2924.76 or later.
What versions of Google Chrome are affected by CVE-2017-5027?
CVE-2017-5027 affects Google Chrome versions prior to 56.0.2924.76 for desktop and versions before 56.0.2924.87 for Android.
What type of attack is facilitated by CVE-2017-5027?
CVE-2017-5027 facilitates remote attacks that allow attackers to execute scripts by bypassing the content security policy.
Is CVE-2017-5027 a cross-site scripting vulnerability?
Yes, CVE-2017-5027 is related to the improper enforcement of content security policy which can lead to cross-site scripting attacks.