CVE-2016-5190 describes an out-of-bounds memory read vulnerability in Google Chrome versions prior to 54.0.2840.59 on Windows, Mac, and Linux, and 54.0.2840.85 on Android. This medium-severity flaw (CVSS 6.3) could be triggered by a remote attacker through crafted HTML pages due to incorrect object lifecycle handling during browser shutdown, potentially leading to low impact on confidentiality, integrity, and availability. There is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. While it has received some community discussion and media coverage, it is not listed in CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 53.0.2785.143CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.