CVE-2017-5033
Blink in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android failed to correctly propagate CSP restrictions to local scheme pages, which allowed a remote attacker to bypass content security policy via a crafted HTML page, related to the unsafe-inline keyword.
- Google Chrome
- ≤ 57.0.2987.75
- Fix
- Available
- CVSS 3.1
- 4.3 MEDIUM
- EPSS
- 1.5% (71th percentile)
- Weakness
- CWE-281
- NVD status
- Modified
- Published
- 2017-04-24
CVE-2017-5033 at NVD
1 known exploit for CVE-2017-5033
Proof-of-concept code and exploit modules indexed by Sploitus