PatchSiren

PatchSiren cyber security CVE debrief

CVE-2017-5928 W3 CVE debrief

CVE-2017-5928 describes a timing side-channel in the W3C High Resolution Time API. The issue can make it easier for remote attackers to conduct AnC attacks from crafted JavaScript, even with a performance.now "Time to Tick" protection mechanism in place. NVD rates the issue LOW (CVSS 3.7).

Vendor
W3
Product
High Resolution Time API
CVSS
LOW 3.7
CISA KEV
Not listed in stored evidence
Original CVE published
2017-02-27
Original CVE updated
2026-05-13
Advisory published
2017-02-27
Advisory updated
2026-05-13

Who should care

Browser vendors, web platform and browser-security engineers, researchers working on timing attacks, and security teams that depend on browser-side timing mitigations or anti-fingerprinting controls.

Technical summary

The supplied NVD record and referenced research indicate that implementations of the High Resolution Time API in various web browsers still allow enough timing precision to measure memory-reference times using a performance.now "Time to Tick" approach. That weakens protections intended to reduce timing leakage and can help remote attackers run AnC attacks with crafted JavaScript. The provided corpus frames this as an API-level issue across browser implementations, not a single vendor-specific product flaw.

Defensive priority

Medium for browser and platform teams, low for most application operators. The disclosed impact is confidentiality-focused and the CVSS score is low, but the issue is relevant anywhere browser timing leakage matters.

Recommended defensive actions

  • Review browser and platform mitigations for high-resolution timing, including timer clamping and related anti-side-channel controls.
  • Use current browser builds and vendor guidance for timing-attack defenses; do not assume performance.now protections fully eliminate fine-grained timing leakage.
  • Track the referenced research and browser-security advisories for implementation-specific exposure and remediation guidance.
  • For sensitive web applications, minimize reliance on client-side secrecy and assume JavaScript timing can still reveal side-channel information.
  • Monitor NVD and browser-vendor updates for changes affecting the High Resolution Time API or related timing primitives.

Evidence notes

This debrief is based only on the supplied NVD record, CVE metadata, and the referenced research/project links in the corpus. The corpus describes an API-level browser timing issue and does not provide a single patched product, affected version list, or exploit instructions. CVSS and weakness data are taken from NVD.

Sources and references

Verified primary and authoritative sources

  • CVE-2017-5928 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2017-5928

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2017-5928 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2017-5928

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.