CVE-2016-1627Google Chrome vulnerability

CWE-2646 documents5 sources
Severity
8.8HIGHNVD
EPSS
1.2%
top 20.70%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 14
Latest updateMay 14

Description

The Developer Tools (aka DevTools) subsystem in Google Chrome before 48.0.2564.109 does not validate URL schemes and ensure that the remoteBase parameter is associated with a chrome-devtools-frontend.appspot.com URL, which allows remote attackers to bypass intended access restrictions via a crafted URL, related to browser/devtools/devtools_ui_bindings.cc and WebKit/Source/devtools/front_end/Runtime.js.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

NVDgoogle/chrome48.0.2564.103

Also affects: Debian Linux 8.0

🔴Vulnerability Details

2
GHSA
GHSA-9v85-hq57-2c7g: The Developer Tools (aka DevTools) subsystem in Google Chrome before 482022-05-14
OSV
CVE-2016-1627: The Developer Tools (aka DevTools) subsystem in Google Chrome before 482016-02-14

📋Vendor Advisories

1
Red Hat
chromium-browser: various fixes from internal audits2016-02-09

💬Community

2
Bugzilla
CVE-2016-3658 libtiff: out-of-bounds read in the TIFFWriteDirectoryTagLongLong8Array function2016-04-12
Bugzilla
CVE-2016-1627 chromium-browser: various fixes from internal audits2016-02-10