CVE-2017-5092 describes an insufficient input validation vulnerability in PPAPI Plugins within Google Chrome versions prior to 60.0.3112.78, affecting Windows, Debian, and other Linux distributions. This high-severity vulnerability (CVSS 8.8) allows a remote unauthenticated attacker to potentially achieve a sandbox escape by enticing a user to visit a crafted HTML page, leading to high impacts on confidentiality, integrity, and availability. While there is no known public exploit code (Metasploit, Nuclei, ExploitDB) or KEV entry, the vulnerability has garnered some community discussion and media coverage, indicating awareness despite its inactive status on the CISA Hot List.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 60.0.3112.78CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.