Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2016-5198

81
FAUCET Score

CVE-2016-5198 is a critical vulnerability in the V8 JavaScript engine affecting Google Chrome on Linux, Android, Windows, and Mac, stemming from incorrect optimization assumptions. This flaw allows a remote attacker to achieve arbitrary read/write operations and ultimately code execution through a specially crafted HTML page. With a CVSS score of 8.8 (HIGH), it presents a significant risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. This vulnerability has been actively exploited in the wild, as indicated by its inclusion in the KEV catalog, and while no public exploit modules like Metasploit or ExploitDB are listed, it has garnered notable community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 54.0.2840.90CPE matchmatch criteria
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
< 54.0.2840.85CPE matchmatch criteria
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
< 54.0.2840.87CPE matchmatch criteria
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
6.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
6.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.8HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
34.70%
Probability of exploitation in next 30 days
EPSS Percentile
98.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Added to KEV · Jun 8, 2022
This CVE's current EPSS score of 0.3470 is in the 99th percentile among its peer group of 14,855 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6 SupplementaryFixed in: chromium-browser-0:54.0.2840.90-1.el6
View patch
googlevendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

redhatCVE-2016-5198Important

chromium-browser: out of bounds memory access in v8

Nov 1, 2016

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
rhn.redhat.com / errata/RHSA-2016-2672.html
Third Party Advisory
chromereleases.googleblog.com / 2016/11/stable-channel-update-for-desktop.html
Release NotesVendor Advisory
crbug.com / 659475
ExploitIssue Tracking
securityfocus.com / bid/94079
Broken LinkThird Party AdvisoryVDB Entry
securitytracker.com / id/1037224
Broken LinkThird Party AdvisoryVDB Entry