CVE-2016-5162 describes a vulnerability in Google Chrome (versions prior to 53.0.2785.89 on Windows/OS X and 53.0.2785.92 on Linux) and related products where the browser failed to properly enforce extension manifest restrictions for IFRAME elements. This flaw could facilitate clickjacking attacks, allowing malicious websites to trick users into unknowingly altering extension settings. Rated as Medium severity (CVSS 6.5), it requires user interaction and network access for exploitation, with a high impact on integrity. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
42.1CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:* | ||
<= 52.0.2743.116CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.