PatchSiren cyber security CVE debrief
CVE-2017-5928 W3 CVE debrief
CVE-2017-5928 describes a timing side-channel in the W3C High Resolution Time API. The issue can make it easier for remote attackers to conduct AnC attacks from crafted JavaScript, even with a performance.now "Time to Tick" protection mechanism in place. NVD rates the issue LOW (CVSS 3.7).
- Vendor
- W3
- Product
- High Resolution Time API
- CVSS
- LOW 3.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-27
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-27
- Advisory updated
- 2026-05-13
Who should care
Browser vendors, web platform and browser-security engineers, researchers working on timing attacks, and security teams that depend on browser-side timing mitigations or anti-fingerprinting controls.
Technical summary
The supplied NVD record and referenced research indicate that implementations of the High Resolution Time API in various web browsers still allow enough timing precision to measure memory-reference times using a performance.now "Time to Tick" approach. That weakens protections intended to reduce timing leakage and can help remote attackers run AnC attacks with crafted JavaScript. The provided corpus frames this as an API-level issue across browser implementations, not a single vendor-specific product flaw.
Defensive priority
Medium for browser and platform teams, low for most application operators. The disclosed impact is confidentiality-focused and the CVSS score is low, but the issue is relevant anywhere browser timing leakage matters.
Recommended defensive actions
- Review browser and platform mitigations for high-resolution timing, including timer clamping and related anti-side-channel controls.
- Use current browser builds and vendor guidance for timing-attack defenses; do not assume performance.now protections fully eliminate fine-grained timing leakage.
- Track the referenced research and browser-security advisories for implementation-specific exposure and remediation guidance.
- For sensitive web applications, minimize reliance on client-side secrecy and assume JavaScript timing can still reveal side-channel information.
- Monitor NVD and browser-vendor updates for changes affecting the High Resolution Time API or related timing primitives.
Evidence notes
This debrief is based only on the supplied NVD record, CVE metadata, and the referenced research/project links in the corpus. The corpus describes an API-level browser timing issue and does not provide a single patched product, affected version list, or exploit instructions. CVSS and weakness data are taken from NVD.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-5928 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-5928
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-5928 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-5928
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.vusec.net/projects/anc
[email protected] - Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.