CVE-2017-5031 describes a use-after-free vulnerability in ANGLE within Google Chrome for Windows, prior to version 57.0.2987.98. This flaw allowed a remote attacker to execute an out-of-bounds memory read by enticing a user to visit a specially crafted HTML page. The vulnerability carries a high CVSS score of 8.8, indicating a critical risk due to its network-based attack vector, low attack complexity, and high potential impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation (not in KEV), no public exploit code (Metasploit, Nuclei, ExploitDB), and a low EPSS score, it garnered some community discussion and media coverage at the time of its disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 57.0.2987.75CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.