CVE-2016-5170 is a high-severity use-after-free vulnerability in WebKit's Blink engine, affecting Google Chrome versions prior to 53.0.2785.113. This flaw arises from improper handling of getter side effects during array key conversion within the Indexed Database (IndexedDB) API. Successful exploitation, typically via user interaction with a malicious website, could lead to a denial of service or potentially allow for arbitrary code execution. There is no evidence of active exploitation, and public exploit code is unavailable, with minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 53.0.2785.101CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.