Arbitrary code execution in Google Chrome - CVE-2016-5177
Published: October 6, 2016 / Updated: June 6, 2021
Vulnerability identifier: #VU807
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-5177
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to cause arbitrary code execution on the target user's system.
The weakness exists due to use-after-free memory error in the V8 engine. By sending a specially crafted content and tricking the victim to upload it attackers can trigger the arbitrary code to be executed.
Successful exploitation of the vulnerability results in arbitrary code execution on the vulnerable system.
The weakness exists due to use-after-free memory error in the V8 engine. By sending a specially crafted content and tricking the victim to upload it attackers can trigger the arbitrary code to be executed.
Successful exploitation of the vulnerability results in arbitrary code execution on the vulnerable system.
Affected software
Google Chrome
Arch Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Fedora
chromium
Arch Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Fedora
chromium
How to mitigate CVE-2016-5177
Update to version 53.0.2785.143.
Google Chrome - update to 53.0.2785.143
chromium - addressed in versions 53.0.2785.143-1.fc24, 53.0.2785.143-1.fc25
chromium - addressed in versions 53.0.2785.143-1.fc24, 53.0.2785.143-1.fc25