CVE-2016-5221 describes a type confusion vulnerability in libGLESv2 within ANGLE, affecting Google Chrome versions prior to 55.0.2883.75 on Mac, Windows, and Linux, and 55.0.2883.84 on Android. This flaw could allow a remote attacker to bypass buffer validation by enticing a user to visit a specially crafted HTML page. Rated Medium severity (CVSS 6.3), successful exploitation could lead to limited confidentiality, integrity, and availability impacts. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or KEV listing, though it garnered some community discussion and media coverage at the time of disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 54.0.2840.99CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.