Learn about CVE-2017-5050 affecting Google Chrome versions before 57.0.2987.98 for Mac, Windows, and Linux, and 57.0.2987.108 for Android. Find out how to mitigate this integer overflow vulnerability.
Google Chrome prior to version 57.0.2987.98 for Mac, Windows, and Linux, and 57.0.2987.108 for Android is affected by an integer overflow vulnerability in FFmpeg. This CVE was published on April 25, 2017.
Understanding CVE-2017-5050
A remote attacker could exploit an integer overflow vulnerability in FFmpeg in Google Chrome versions before 57.0.2987.98 (for Mac, Windows, and Linux) and 57.0.2987.108 (for Android) by using a specially crafted video file. This vulnerability is associated with the ChunkDemuxer and can lead to an out of bounds memory write.
What is CVE-2017-5050?
The Impact of CVE-2017-5050
Technical Details of CVE-2017-5050
Google Chrome prior to version 57.0.2987.98 for Mac, Windows, and Linux, and 57.0.2987.108 for Android is affected by an integer overflow vulnerability in FFmpeg.
Vulnerability Description
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Google Chrome users should take immediate steps to address CVE-2017-5050:
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates