CVE-2017-5112 describes a heap buffer overflow vulnerability in WebGL within Google Chrome versions prior to 61.0.3163.79 on Windows. This critical flaw, rated 8.8 HIGH, allowed a remote attacker to execute arbitrary code within the browser's sandbox by enticing a user to visit a specially crafted HTML page. While no public exploit code is available (Metasploit, Nuclei, ExploitDB), the vulnerability garnered significant community discussion and media coverage at the time of its disclosure. It is not listed in CISA's KEV catalog, indicating no known active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 61.0.3163.79CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.