cve/2016/CVE-2016-5208.md
2024-05-26 14:27:05 +02:00

1001 B

CVE-2016-5208

Description

Blink in Google Chrome prior to 55.0.2883.75 for Linux and Windows, and 55.0.2883.84 for Android allowed possible corruption of the DOM tree during synchronous event handling, which allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.

POC

Reference

Github