CVE-2017-5006 describes a Universal Cross-Site Scripting (UXSS) vulnerability in Google Chrome versions prior to 56.0.2924.76 on Linux, Windows, and Mac, and 56.0.2924.87 on Android. This flaw stemmed from incorrect handling of object owner relationships within the Blink rendering engine, allowing a remote attacker to inject arbitrary scripts or HTML via a specially crafted web page. The vulnerability carries a CVSS v3.0 score of 6.1 (Medium), indicating it can be exploited remotely with low attack complexity, requiring user interaction. A successful exploit could lead to limited confidentiality and integrity impacts, as an attacker could potentially steal sensitive information or deface web content. There is no evidence of active exploitation (KEV list), nor are there public exploits available in Metasploit, Nuclei, or ExploitDB. Despite this, the vulnerability has garnered significant community discussion and media coverage, suggesting a high level of awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 55.0.2883.87CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.