CVE-2016-5181 describes a Universal Cross-Site Scripting (UXSS) vulnerability in Google Chrome's Blink rendering engine, affecting versions prior to 54.0.2840.59 on Windows, Mac, and Linux, and 54.0.2840.85 on Android. This flaw allowed remote attackers to inject arbitrary scripts or HTML through specially crafted web pages due to improper handling of v8 microtasks while the DOM was in an inconsistent state. Rated as Medium severity with a CVSS 3.0 score of 6.1, it requires user interaction (UI:R) and network access (AV:N) to achieve partial confidentiality and integrity impact (C:L/I:L). There is no evidence of active exploitation, no public exploit code available in Metasploit, Nuclei, or ExploitDB, and it has received minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 53.0.2785.143CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.