CVE-2016-5155 describes a vulnerability in Google Chrome versions prior to 53.0.2785.89 on Windows/OS X and 53.0.2785.92 on Linux, as well as related products like OpenSUSE Chrome/Leap. This flaw allows remote attackers to spoof the address bar through a crafted website due to improper validation of initial document access. Rated Medium (CVSS 6.5), it requires user interaction (UI:R) but has high impact on integrity (I:H), meaning an attacker could deceive users into believing they are on a legitimate site. There is no known active exploitation, public exploit code (Metasploit/Nuclei/ExploitDB), or KEV listing, and community discussion is minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 52.0.2743.116CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
42.1CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.