CVE-2017-5020 PUBLISHED

Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, failed to require a user gesture for powerful download operations, which allowed a remote attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted HTML page.

EPSS 0.53% · 67.1th percentile

Risk Scores

EPSS Score
0.53%
67.1th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSchromium-browser0, 45.0.2454.101-0ubuntu1.1201, 47.0.2526.73-0ubuntu1.1218
Ubuntu:14.04:LTSchromium-browser43.0.2357.81-0ubuntu0.14.04.1.1089, 43.0.2357.130-0ubuntu0.14.04.1.1092, 44.0.2403.89-0ubuntu0.14.04.1.1095

Timeline

References

Open in Interactive Console →