CVE-2016-5149 is a high-severity vulnerability affecting Google Chrome versions prior to 53.0.2785.89 on Windows/OS X and 53.0.2785.92 on Linux, as well as related products like openSUSE Chrome/Leap. It allows remote attackers to perform extension-bindings injection attacks by exploiting the extensions subsystem's reliance on IFRAME source URLs, leveraging script access to about:blank resources. With a CVSS score of 8.8 (High), this vulnerability has a network attack vector, low attack complexity, and can lead to high impacts on confidentiality, integrity, and availability. While there is no evidence of active exploitation (not in KEV or Hot List) and no public exploit code (Metasploit, Nuclei, ExploitDB), it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 52.0.2743.116CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
42.1CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.