CVE-2016-5166 describes a vulnerability in Google Chrome (versions prior to 53.0.2785.89 on Windows/OS X and 53.0.2785.92 on Linux) where saving an HTTP-referenced file:// URL could expose NetNTLM hashes. This low-severity vulnerability (CVSS 3.1) requires user interaction ("Save page as") and a crafted web page to facilitate SMB relay attacks. There is no evidence of active exploitation, public exploit code, or significant community discussion, indicating a low current risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 52.0.2743.116CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
42.1CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.