CVE-2016-1625Google Chrome vulnerability

CWE-2646 documents5 sources
Severity
4.3MEDIUMNVD
EPSS
0.6%
top 29.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 14
Latest updateMay 14

Description

The Chrome Instant feature in Google Chrome before 48.0.2564.109 does not ensure that a New Tab Page (NTP) navigation target is on the most-visited or suggestions list, which allows remote attackers to bypass intended restrictions via unspecified vectors, related to instant_service.cc and search_tab_helper.cc.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages2 packages

NVDgoogle/chrome48.0.2564.103

Also affects: Debian Linux 8.0

🔴Vulnerability Details

2
GHSA
GHSA-2vrm-g9h8-5755: The Chrome Instant feature in Google Chrome before 482022-05-14
OSV
CVE-2016-1625: The Chrome Instant feature in Google Chrome before 482016-02-14

📋Vendor Advisories

1
Red Hat
chromium-browser: navigation bypass in Chrome Instant2016-02-09

💬Community

2
Bugzilla
CVE-2016-3658 libtiff: out-of-bounds read in the TIFFWriteDirectoryTagLongLong8Array function2016-04-12
Bugzilla
CVE-2016-1625 chromium-browser: navigation bypass in Chrome Instant2016-02-10