CVE-2016-5220 describes a vulnerability in PDFium, the PDF rendering engine used by Google Chrome prior to versions 55.0.2883.75 (desktop) and 55.0.2883.84 (Android). This flaw allowed a remote attacker to read local files on a user's system by tricking them into opening a specially crafted PDF document. The vulnerability has a CVSS score of 6.5 (Medium), indicating a network-based attack with low complexity, requiring user interaction, and resulting in high confidentiality impact. While there is no evidence of active exploitation (not in KEV or Hot List) and no public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability received moderate community discussion and media coverage at the time of its disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 54.0.2840.99CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.