Arbitrary code execution in Google Chrome - CVE-2016-5178

 

Arbitrary code execution in Google Chrome - CVE-2016-5178

Published: October 6, 2016 / Updated: June 6, 2021


Vulnerability identifier: #VU808
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-5178
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause arbitrary code execution on the target user's system.
The weakness exists due to insufficient input validation. By sending a specially crafted content and tricking the victim to upload it attackers can trigger the arbitrary code to be executed.
Successful exploitation of the vulnerability results in arbitrary code execution on the vulnerable system.

Affected software

Google Chrome
Arch Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Fedora
chromium

How to mitigate CVE-2016-5178

Update to version 53.0.2785.143.

Google Chrome - update to 53.0.2785.143
chromium - addressed in versions 53.0.2785.143-1.fc24, 53.0.2785.143-1.fc25

External References

Related Security Bulletins