First published: Tue Jun 06 2017(Updated: )
Failure to take advantage of available mitigations in credit card autofill in Google Chrome prior to 59.0.3071.92 for Android allowed a local attacker to take screen shots of credit card information via a crafted HTML page.
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/Chrome | <59.0.3071.86 | 59.0.3071.86 |
Google Chrome (Trace Event) | <59.0.3071.92 | |
Android |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-5082 is considered a moderate severity vulnerability due to its potential for information disclosure.
To fix CVE-2017-5082, update Google Chrome to version 59.0.3071.92 or later on Android.
CVE-2017-5082 can be exploited by a local attacker with access to the device running vulnerable versions of Google Chrome.
CVE-2017-5082 may expose sensitive credit card information through crafted HTML pages.
Google Chrome versions prior to 59.0.3071.92 for Android are affected by CVE-2017-5082.