PatchSiren

PatchSiren cyber security CVE debrief

CVE-2016-5210 Google CVE debrief

CVE-2016-5210 is a high-severity Google Chrome vulnerability involving a heap buffer overflow during TIFF image parsing in PDFium. According to the CVE description, a crafted PDF file could trigger heap corruption remotely. The supplied NVD data rates the issue 8.8 (HIGH) with network attack vector, low attack complexity, no privileges required, and required user interaction.

Vendor
Google
Product
Chrome
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2017-01-19
Original CVE updated
2026-05-13
Advisory published
2017-01-19
Advisory updated
2026-05-13

Who should care

Chrome administrators, endpoint security teams, Android fleet managers, and anyone responsible for users or services that open untrusted PDF files should prioritize this issue on affected pre-fix Chrome builds.

Technical summary

The supplied record describes a heap buffer overflow in PDFium’s TIFF image parsing path, classified as CWE-787. The NVD CVSS vector is CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, which indicates a network-reachable flaw that still depends on user interaction with a crafted PDF to trigger the vulnerable code path.

Defensive priority

High

Recommended defensive actions

  • Update Google Chrome to the vendor-fixed release for your platform, including Android, using official vendor guidance.
  • Verify that managed Chrome fleets are not pinned to affected versions and that automatic updates remain enabled.
  • Prioritize patching endpoints and shared systems that routinely open untrusted PDF content.
  • Review document-handling workflows that accept external PDFs and reduce exposure where possible.
  • Cross-check the Google Chrome stable-channel update and Chromium issue references if you use extended-stable, pinned, or enterprise-managed Chrome versions, because the supplied record shows differing version ranges.

Evidence notes

The CVE description in the supplied corpus states that a heap buffer overflow during TIFF image parsing in PDFium could allow remote heap corruption via a crafted PDF file. The NVD metadata classifies the weakness as CWE-787 and lists CVSS 3.0 AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. The same record also references Google’s Chrome stable-channel update, a Chromium issue tracker entry, Red Hat errata, SecurityFocus, and Gentoo GLSA. One point to validate operationally is the version scope: the descriptive text mentions fixes before 55.0.2883.75 on desktop and 55.0.2883.84 on Android, while the NVD CPE range shown in the supplied metadata ends at 54.0.2840.99.

Sources and references

Verified primary and authoritative sources

  • CVE-2016-5210 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2016-5210

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2016-5210 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2016-5210

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.