CVE-2016-5226 describes a cross-site scripting (XSS) vulnerability in Google Chrome versions prior to 55.0.2883.75 across Linux, Windows, and Mac. This flaw allowed a user to self-XSS by dragging and dropping a javascript: URL into the URL bar, executing malicious JavaScript in the context of the current tab. With a CVSS score of 6.1 (Medium), it requires user interaction and social engineering, leading to potential low impact on confidentiality and integrity. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion, indicating a low exploitation status.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 54.0.2840.99CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.