CVE-2017-5082: Infoleak
An insufficient hardening flaw was found in the credit card editor component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=721579
External References:
https://chromereleases.googleblog.com/2017/06/stable-channel-update-for-desktop.html
Other sources
Failure to take advantage of available mitigations in credit card autofill in Google Chrome prior to 59.0.3071.92 for Android allowed a local attacker to take screen shots of credit card information via a crafted HTML page.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5082?
CVE-2017-5082 is considered a moderate severity vulnerability due to its potential for information disclosure.
How do I fix CVE-2017-5082?
To fix CVE-2017-5082, update Google Chrome to version 59.0.3071.92 or later on Android.
Who can exploit CVE-2017-5082?
CVE-2017-5082 can be exploited by a local attacker with access to the device running vulnerable versions of Google Chrome.
What type of information may be exposed due to CVE-2017-5082?
CVE-2017-5082 may expose sensitive credit card information through crafted HTML pages.
Which versions of Google Chrome are affected by CVE-2017-5082?
Google Chrome versions prior to 59.0.3071.92 for Android are affected by CVE-2017-5082.