CVE-2017-5020 describes a vulnerability in Google Chrome versions prior to 56.0.2924.76 (Linux, Windows, Mac) and 56.0.2924.87 (Android). This flaw allowed a remote attacker to execute arbitrary code by convincing a user to install a malicious extension, then directing them to a crafted HTML page, as powerful download operations did not require a user gesture. Rated Medium with a CVSS score of 6.1, the attack vector is network-based with low complexity, requiring user interaction. The potential impact involves low confidentiality and integrity compromise, with no availability impact. There is no indication of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Despite this, the vulnerability has garnered some community attention and media coverage, suggesting awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 55.0.2883.87CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.