CVE-2016-5213 describes a use-after-free vulnerability in the V8 JavaScript engine within Google Chrome versions prior to 55.0.2883.75 for desktop and 55.0.2883.84 for Android. This flaw allowed a remote attacker to potentially achieve heap corruption by enticing a user to visit a specially crafted HTML page. With a CVSS score of 8.8 (High), this vulnerability presented a significant risk, as it could lead to high impacts on confidentiality, integrity, and availability with low attack complexity. While the vulnerability received some community discussion and media coverage at the time, there is no evidence of active exploitation, readily available exploit code in common repositories, or inclusion in CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 54.0.2840.99CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.