CVE-2017-5081: Input Validation
Lack of verification of an extension's locale folder in Google Chrome prior to 59.0.3071.86 for Mac, Windows, and Linux, and 59.0.3071.92 for Android, allowed an attacker with local write access to modify extensions by modifying extension files.
Other sources
The following flaw was identified in the Chromium browser: extension verification bypass.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=672008
External References:
https://chromereleases.googleblog.com/2017/06/stable-channel-update-for-desktop.html
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5081?
CVE-2017-5081 is considered a medium severity vulnerability due to its potential to allow an attacker to modify extension files.
How do I fix CVE-2017-5081?
To fix CVE-2017-5081, update Google Chrome to version 59.0.3071.86 or later.
What versions of Google Chrome are affected by CVE-2017-5081?
CVE-2017-5081 affects Google Chrome versions prior to 59.0.3071.86 on Mac, Windows, Linux, and 59.0.3071.92 on Android.
Who can exploit CVE-2017-5081?
An attacker with local write access can exploit CVE-2017-5081 to modify extension files.
What systems are vulnerable to CVE-2017-5081?
CVE-2017-5081 impacts Google Chrome on various systems including Mac, Windows, and Linux.