CVE-2016-5156 is a use-after-free vulnerability in Google Chrome's event bindings, specifically in extensions/renderer/event_bindings.cc, affecting versions before 53.0.2785.89 on Windows/OS X and 53.0.2785.92 on Linux, as well as OpenSUSE Chrome and Leap. This high-severity vulnerability (CVSS 8.8) allows remote attackers to cause a denial of service or potentially have other significant impact through user interaction, due to the system attempting to process filtered events after failing to add an event matcher. While it has a high FAUCET Risk Score of 72/100 and has received some media coverage, there is no evidence of active exploitation, no known exploit code in Metasploit or ExploitDB, and it is not listed in the KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
42.1CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:* | ||
<= 52.0.2743.116CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.