CVE-2016-5130 describes a URL spoofing vulnerability in Google Chrome versions prior to 52.0.2743.82, specifically within the content/renderer/history_controller.cc component. This medium-severity vulnerability (CVSS 6.5) allows remote attackers to manipulate the displayed URL via a crafted website by improperly utilizing the JavaScript forward method. Exploitation requires user interaction (UI:R) but has a low attack complexity (AC:L) and can lead to high integrity impact (I:H) by deceiving users about the true URL. While there is no known active exploitation or publicly available exploit code, the vulnerability garnered some community attention and media coverage upon its disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 51.0.2704.106CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.