CVE-2017-5084: Google Chrome OS

Low severity, CVSS 3.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Inappropriate implementation in image-burner in Google Chrome OS prior to 59.0.3071.92 allowed a local attacker to read local files via dbus-send commands to a BurnImage D-Bus endpoint.

Affected products

  • Google Chrome OS: before 59.0.3071.92 (fixed in 59.0.3071.92)

Published 2017-10-27. Last modified 2026-06-17.