CVE

Id
101840  
CVE No.
CVE-2017-5020  
Status
Candidate  
Description
Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, failed to require a user gesture for powerful download operations, which allowed a remote attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted HTML page.  
Phase
Assigned (20170102)  
Votes
None (candidate not yet proposed)  
Comments