CVE-2017-5012 describes a heap buffer overflow vulnerability in the V8 JavaScript engine affecting Google Chrome versions prior to 56.0.2924.76 on Linux, Windows, and Mac, and 56.0.2924.87 on Android. This critical flaw, rated 8.8 HIGH, could allow a remote attacker to achieve heap corruption and potentially execute arbitrary code by enticing a user to visit a specially crafted HTML page. While there is no evidence of active exploitation (KEV) or public exploit code (Metasploit, ExploitDB), the vulnerability garnered significant community discussion and media coverage at the time of its disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 55.0.2883.87CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.