PatchSiren

PatchSiren cyber security CVE debrief

CVE-2017-5014 Google CVE debrief

CVE-2017-5014 describes a heap buffer overflow in Skia image processing used by Google Chrome. A remote attacker could trigger the issue with a crafted HTML page, leading to an out-of-bounds memory read and limited impact on confidentiality, integrity, and availability. Google’s linked Chrome release advisory and downstream security advisories indicate the issue was fixed in Chrome updates released in January 2017.

Vendor
Google
Product
Chrome
CVSS
MEDIUM 6.3
CISA KEV
Not listed in stored evidence
Original CVE published
2017-02-17
Original CVE updated
2026-05-13
Advisory published
2017-02-17
Advisory updated
2026-05-13

Who should care

Organizations that manage Google Chrome on desktops or Android, especially endpoint, browser, and patch-management teams, should care. Security teams should also pay attention if Chrome is used to open untrusted web content or embedded HTML.

Technical summary

The vulnerability is recorded as a heap-based memory corruption issue in Skia during image processing, with CWE-119 assigned in the NVD record. The NVD description states that a crafted HTML page could trigger a remote out-of-bounds memory read in Chrome versions prior to 56.0.2924.76 on Linux, Windows, and Mac, and prior to 56.0.2924.87 on Android. The linked NVD record also lists Chrome version coverage through 55.0.2883.87 in its CPE criteria, so readers should treat the advisory text and product-mapping data together.

Defensive priority

Medium. The flaw is remotely triggerable through web content, but the supplied record does not indicate known exploitation in the wild or KEV inclusion.

Recommended defensive actions

  • Upgrade Google Chrome to a fixed release at or above the versions listed in the CVE description.
  • Prioritize patching managed desktops and Android devices that may browse untrusted content.
  • Use centralized browser update enforcement and verify versions across fleets.
  • Monitor vendor advisories and downstream distro notices linked in the record for remediation guidance.
  • Treat unexpected browser crashes or rendering anomalies as signals to investigate and update promptly.

Evidence notes

All statements are based on the supplied NVD/CVE corpus and the linked official references. The record identifies the issue as CVE-2017-5014, published 2017-02-17 and modified 2026-05-13, with references to the Chrome stable-channel release note, Chromium issue 675332, and downstream security advisories from Red Hat, Debian, and Gentoo. No KEV date or ransomware linkage is present in the supplied data.

Sources and references

Verified primary and authoritative sources

  • CVE-2017-5014 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2017-5014

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2017-5014 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2017-5014

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.