CVE-2016-5205 describes a Universal Cross-Site Scripting (UXSS) vulnerability in Google Chrome versions prior to 55.0.2883.75 on Linux, Windows, and Mac. This flaw allowed remote attackers to inject arbitrary scripts or HTML into a user's browser via a specially crafted HTML page due to improper handling of deferred page loads. With a CVSS score of 6.1 (Medium), exploitation requires user interaction (UI:R) and could lead to limited confidentiality and integrity impacts (C:L/I:L). While there is no evidence of active exploitation or publicly available exploit code, the vulnerability garnered significant community discussion and media coverage at the time of its disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 54.0.2840.99CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.