First published: Tue Jun 06 2017(Updated: )
A use after free in credit card autofill in Google Chrome prior to 59.0.3071.86 for Linux and Windows allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/Chrome | <59.0.3071.86 | 59.0.3071.86 |
Google Chrome (Trace Event) | <59.0.3071.86 | |
Linux Kernel | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-5080 has a moderate severity rating as it involves a use after free vulnerability in the Chrome browser's credit card autofill feature.
To fix CVE-2017-5080, update Google Chrome to version 59.0.3071.86 or later.
CVE-2017-5080 affects Google Chrome versions prior to 59.0.3071.86.
Yes, CVE-2017-5080 can be exploited remotely through a crafted HTML page.
The vulnerability in CVE-2017-5080 is found in the credit card autofill component of Google Chrome.