Security Advisory

CVE-2016-5218

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-01-19 05:43:00
Last updated 2024-08-06 00:53:48
Assigner Chrome
CVSS score not scored
State PUBLISHED

Description

The extensions API in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android incorrectly handled navigation within PDFs, which allowed a remote attacker to temporarily spoof the contents of the Omnibox (URL bar) via a crafted HTML page containing PDF data.