CVE-2017-5107 impacted Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac, allowing a remote attacker to extract pixel values from a cross-origin page. Learn about the impact, technical details, and mitigation steps.
Google Chrome prior to version 60.0.3112.78 for Linux, Windows, and Mac had a vulnerability related to SVG rendering that allowed a remote attacker to retrieve pixel values from a cross-origin page.
Understanding CVE-2017-5107
Before version 60.0.3112.78, Google Chrome had a vulnerability related to SVG rendering on Linux, Windows, and Mac platforms. This vulnerability, known as a timing attack, was exploited by a remote attacker to retrieve pixel values from a cross-origin page that was being embedded within an iframe, using a specially crafted HTML page.
What is CVE-2017-5107?
The Impact of CVE-2017-5107
Technical Details of CVE-2017-5107
Google Chrome prior to version 60.0.3112.78 for Linux, Windows, and Mac was affected by the following:
Vulnerability Description
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Immediate Steps to Take: