CVE-2016-5219 describes a heap use-after-free vulnerability in the V8 JavaScript engine within Google Chrome versions prior to 55.0.2883.75 on Mac, Windows, and Linux, and 55.0.2883.84 on Android. This flaw could allow a remote attacker to potentially achieve heap corruption by enticing a user to visit a specially crafted HTML page. With a CVSS score of 6.3 (Medium), this vulnerability requires user interaction (UI:R) and has low impacts on confidentiality, integrity, and availability (C:L/I:L/A:L). The attack vector is network-based (AV:N) with low attack complexity (AC:L). There is no evidence of active exploitation (KEV: No, Hot List: Inactive), and no public exploit code is available on Metasploit, Nuclei, or ExploitDB. Despite this, the CVE garnered some community discussion and media coverage at the time of its disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 54.0.2840.99CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.