CVE-2016-5183 is a heap use-after-free vulnerability in PDFium, affecting Google Chrome versions prior to 54.0.2840.59 on Windows, Mac, and Linux, and 54.0.2840.85 on Android. This high-severity vulnerability (CVSS 8.8) allows a remote attacker to potentially exploit heap corruption by enticing a user to open a crafted PDF file, leading to high impacts on confidentiality, integrity, and availability. While no known public exploits (Metasploit, Nuclei, ExploitDB) exist and it's not in the KEV catalog, it has garnered some community discussion and media coverage, indicating awareness despite its inactive Hot List status.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 53.0.2785.143CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.