CVE-2017-5022 describes a vulnerability in Google Chrome versions prior to 56.0.2924.76 (Linux, Windows, Mac) and 56.0.2924.87 (Android) where the browser failed to properly enforce the unsafe-inline Content Security Policy. This medium-severity vulnerability (CVSS 4.3) allows a remote attacker to bypass CSP via a crafted HTML page, potentially leading to information disclosure (I:L) with no confidentiality or availability impact. There is no evidence of active exploitation, no known public exploit code (Metasploit, Nuclei, ExploitDB), and it is not listed in CISA's KEV catalog, despite some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 55.0.2883.87CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.