CVE-2016-5147 describes a Universal Cross-Site Scripting (UXSS) vulnerability in Blink, the rendering engine used by Google Chrome versions prior to 53.0.2785.89 on Windows/OS X and 53.0.2785.92 on Linux, due to mishandling of deferred page loads. This medium-severity vulnerability (CVSS 6.1) allows remote attackers to inject arbitrary web script or HTML via a crafted website, requiring user interaction but potentially leading to low impact on confidentiality and integrity. There is no evidence of active exploitation, publicly available exploit code, or inclusion in the CISA KEV catalog, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 52.0.2743.116CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.