CVE-2017-5074 is a use-after-free vulnerability in Chrome Apps within Google Chrome for Windows, affecting versions prior to 59.0.3071.86. A remote attacker could exploit this by tricking a user into visiting a crafted HTML page, leading to an out-of-bounds memory read related to Bluetooth functionality. This vulnerability carries a high CVSS score of 8.0, indicating a high potential for impact on confidentiality, integrity, and availability, with an adjacent network attack vector and user interaction required. While there is no evidence of active exploitation, public exploit code, or KEV listing, the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 59.0.3071.86CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.