CVE-2017-5080: Use After Free
A use after free in credit card autofill in Google Chrome prior to 59.0.3071.86 for Linux and Windows allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
Other sources
An use after free flaw was found in the credit card autofill component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=708819
External References:
https://chromereleases.googleblog.com/2017/06/stable-channel-update-for-desktop.html
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5080?
CVE-2017-5080 has a moderate severity rating as it involves a use after free vulnerability in the Chrome browser's credit card autofill feature.
How do I fix CVE-2017-5080?
To fix CVE-2017-5080, update Google Chrome to version 59.0.3071.86 or later.
What versions of Chrome are affected by CVE-2017-5080?
CVE-2017-5080 affects Google Chrome versions prior to 59.0.3071.86.
Can CVE-2017-5080 be exploited remotely?
Yes, CVE-2017-5080 can be exploited remotely through a crafted HTML page.
What component of Chrome is vulnerable in CVE-2017-5080?
The vulnerability in CVE-2017-5080 is found in the credit card autofill component of Google Chrome.