CVE-2016-5214 describes a vulnerability in Google Chrome prior to version 55.0.2883.75 for Windows, where a crafted HTML page could prevent downloaded files from receiving the Mark of the Web. This medium-severity vulnerability has a CVSS score of 4.3, indicating a low impact on integrity (I:L) and requiring user interaction (UI:R) for exploitation. There is no evidence of active exploitation, readily available exploit code in common frameworks like Metasploit or ExploitDB, and it has received minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 54.0.2840.99CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.