CVE-2016-5208 describes a DOM tree corruption vulnerability in Blink, affecting Google Chrome versions prior to 55.0.2883.75 on Linux and Windows, and 55.0.2883.84 on Android. This flaw allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) through a specially crafted HTML page. With a CVSS score of 6.1 (Medium), exploitation requires user interaction (UI:R) and could lead to low impact on confidentiality and integrity (C:L/I:L). While not listed in CISA's KEV catalog and lacking public exploit code in Metasploit, Nuclei, or ExploitDB, the vulnerability garnered significant community discussion and media coverage at the time of its disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 54.0.2840.99CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.