CVE-2016-5137 is a vulnerability in Google Chrome versions prior to 52.0.2743.82, specifically within the Content Security Policy (CSP) implementation in Blink. It allowed remote attackers to infer whether a user had visited a specific HSTS (HTTP Strict Transport Security) website by reading CSP reports, due to improper policy application between HTTP/HTTPS and WS/WSS protocols. This medium-severity vulnerability (CVSS 4.3) has a low impact on confidentiality, requiring user interaction (UI:R) but low attack complexity (AC:L). There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in the KEV catalog. Despite this, it garnered significant community discussion and media coverage at the time of its disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 51.0.2704.106CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.