CVE-2016-5210 describes a heap buffer overflow vulnerability in PDFium, the PDF rendering engine used by Google Chrome prior to versions 55.0.2883.75 (desktop) and 55.0.2883.84 (Android). This flaw could be triggered by a remote attacker through a specially crafted PDF file, potentially leading to heap corruption. With a CVSS score of 8.8 (High), it presents a significant risk, allowing for high impact on confidentiality, integrity, and availability with low attack complexity and no user interaction beyond opening the malicious file. While the vulnerability received notable media coverage and community discussion, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 54.0.2840.99CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.