CVE-2016-5224 describes a timing attack vulnerability in Google Chrome's Blink rendering engine, specifically affecting SVG filters' handling of denormalized floating-point arithmetic. This flaw, present in Chrome versions prior to 55.0.2883.75 (desktop) and 55.0.2883.84 (Android), allowed a remote attacker to bypass the Same Origin Policy through a specially crafted HTML page. With a CVSS score of 4.3 (Medium), it requires user interaction (UI:R) and has a low impact on integrity (I:L), meaning an attacker could potentially modify limited data. There is no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed in CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 54.0.2840.99CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.