CVE-2017-5056 is a use-after-free vulnerability in Blink, affecting Google Chrome versions prior to 57.0.2987.133 on Linux, Windows, and Mac, and 57.0.2987.132 on Android. This flaw allows a remote attacker to achieve an out-of-bounds memory read by enticing a user to visit a specially crafted HTML page. It carries a high CVSS score of 8.8, indicating a critical risk due to its network-based attack vector, low attack complexity, and high potential for confidentiality, integrity, and availability impacts. While there is no evidence of active exploitation (not in KEV) and no public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability garnered significant community discussion and media coverage, suggesting awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 57.0.2987.133CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 57.0.2987.132CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.