CVE-2016-1655Google Chrome vulnerability

7 documents7 sources
Severity
8.8HIGHNVD
EPSS
3.0%
top 13.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 18
Latest updateMay 14

Description

Google Chrome before 50.0.2661.75 does not properly consider that frame removal may occur during callback execution, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted extension.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

NVDgoogle/chrome49.0.2623.112
NVDopensuse/leap42.1

Also affects: Debian Linux 8.0, Linux Enterprise 12.0, Ubuntu Linux 14.04, 15.10, 16.04

🔴Vulnerability Details

3
GHSA
GHSA-885j-2qcc-hmjh: Google Chrome before 502022-05-14
CVEList
CVE-2016-1655: Google Chrome before 502016-04-18
OSV
CVE-2016-1655: Google Chrome before 502016-04-18

📋Vendor Advisories

2
Ubuntu
Oxide vulnerabilities2016-04-27
Red Hat
chromium-browser: use-after-free related to extensions2016-04-13

💬Community

1
Bugzilla
CVE-2016-1655 chromium-browser: use-after-free related to extensions2016-04-14
CVE-2016-1655 — Google Chrome vulnerability | cvebase