CVE-2016-5223 describes an integer overflow vulnerability in PDFium, the PDF rendering engine used by Google Chrome. This flaw, present in versions prior to 55.0.2883.75 for desktop and 55.0.2883.84 for Android, could be triggered by a remote attacker through a specially crafted PDF file. Successful exploitation could lead to heap corruption or a denial-of-service condition. Rated as Medium severity (CVSS 6.5), it requires user interaction (UI:R) to open the malicious PDF, but has low attack complexity (AC:L) and no authentication required (PR:N). While there is no evidence of active exploitation (KEV: No) and no public exploit code (Metasploit, Nuclei, ExploitDB: None), the vulnerability received some community attention and media coverage at the time of its disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 54.0.2840.99CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.