CVE-2016-5202 describes a critical vulnerability in Google Chrome versions prior to 54.0.2840.98 on macOS, 54.0.2840.99 on Windows, and 54.0.2840.100 on Linux, specifically within the browser/extensions/api/dial/dial_registry.cc component. This flaw, rated 9.1 CRITICAL (CVSSv3.1), allows an unauthenticated attacker to remotely access and destroy sensitive data due to improper handling of device IDs during an erase operation. While the vulnerability has a high severity and potential for data compromise, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion beyond a single mention and one media article.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 54.0.2840.98CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 54.0.2840.99CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 54.0.2840.100CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.