CVE-2016-5127 is a use-after-free vulnerability in the Blink rendering engine, specifically within WebKit/Source/core/editing/VisibleUnits.cpp, affecting Google Chrome versions prior to 52.0.2743.82. This flaw can be triggered remotely by crafted JavaScript code interacting with @import at-rules in CSS and LINK elements with rel=import attributes. With a CVSSv3 score of 7.5 (High), successful exploitation could lead to a denial of service or potentially arbitrary code execution, requiring user interaction and high attack complexity. There is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed in CISA's KEV catalog, though it garnered significant community discussion and media coverage at the time of disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 51.0.2704.106CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.