Arbitrary code execution in Google Chrome - CVE-2016-5178

 

Arbitrary code execution in Google Chrome - CVE-2016-5178

Published: October 6, 2016 / Updated: June 6, 2021


Vulnerability identifier: #VU808
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2016-5178
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Google
Affected software:
Google Chrome

Detailed vulnerability description

The vulnerability allows a remote user to cause arbitrary code execution on the target user's system.
The weakness exists due to insufficient input validation. By sending a specially crafted content and tricking the victim to upload it attackers can trigger the arbitrary code to be executed.
Successful exploitation of the vulnerability results in arbitrary code execution on the vulnerable system.

How to mitigate CVE-2016-5178

Update to version 53.0.2785.143.

Sources