Arbitrary code execution in Google Chrome - CVE-2016-5177

 

Arbitrary code execution in Google Chrome - CVE-2016-5177

Published: October 6, 2016 / Updated: June 6, 2021


Vulnerability identifier: #VU807
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2016-5177
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Google
Affected software:
Google Chrome

Detailed vulnerability description

The vulnerability allows a remote user to cause arbitrary code execution on the target user's system.
The weakness exists due to use-after-free memory error in the V8 engine. By sending a specially crafted content and tricking the victim to upload it attackers can trigger the arbitrary code to be executed.
Successful exploitation of the vulnerability results in arbitrary code execution on the vulnerable system.

How to mitigate CVE-2016-5177

Update to version 53.0.2785.143.

Sources