CVE-2016-5204 describes a DOM tree corruption vulnerability in Google Chrome (prior to versions 55.0.2883.75 for desktop and 55.0.2883.84 for Android) caused by the leaking of an SVG shadow tree. This flaw allows a remote attacker to inject arbitrary scripts or HTML (UXSS) through a specially crafted HTML page. The vulnerability has a CVSSv3 score of 6.1 (Medium), indicating a network-based attack requiring user interaction with low attack complexity, potentially leading to limited confidentiality and integrity impacts. There is no evidence of active exploitation, readily available exploit code in common frameworks, or inclusion in CISA's KEV catalog, though it has received some community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 54.0.2840.99CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.