CVE-2017-5074: Use After Free
A use after free in Chrome Apps in Google Chrome prior to 59.0.3071.86 for Windows allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page, related to Bluetooth.
Other sources
An use after free flaw was found in the Apps Bluetooth component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=700040
External References:
https://chromereleases.googleblog.com/2017/06/stable-channel-update-for-desktop.html
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5074?
CVE-2017-5074 has been classified as a high-severity vulnerability due to its potential for exploitation through crafted HTML pages.
How do I fix CVE-2017-5074?
To fix CVE-2017-5074, update Google Chrome to version 59.0.3071.86 or later.
What types of attacks are possible with CVE-2017-5074?
CVE-2017-5074 allows remote attackers to perform an out of bounds memory read, which can lead to information disclosure.
Which versions of Google Chrome are affected by CVE-2017-5074?
CVE-2017-5074 affects all versions of Google Chrome prior to 59.0.3071.86.
Is CVE-2017-5074 specific to any operating systems?
CVE-2017-5074 specifically affects Google Chrome on Windows platforms before the mentioned version.