Severity
4.3MEDIUM
EPSS
0.9%
top 24.61%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 18
Latest updateMay 14

Description

The Extensions subsystem in Google Chrome before 50.0.2661.75 incorrectly relies on GetOrigin method calls for origin comparisons, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted extension.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages4 packages

NVDgoogle/chrome49.0.2623.112
Ubuntuchromium-browser< 50.0.2661.102-0ubuntu0.14.04.1.1117+1
NVDopensuse/leap42.1

Also affects: Debian Linux 8.0

🔴Vulnerability Details

3
GHSA
GHSA-jqq4-q4jg-35ch: The Extensions subsystem in Google Chrome before 502022-05-14
OSV
CVE-2016-1658: The Extensions subsystem in Google Chrome before 502016-04-18
CVEList
CVE-2016-1658: The Extensions subsystem in Google Chrome before 502016-04-18

📋Vendor Advisories

1
Red Hat
chromium-browser: potential leak of sensitive information to malicious extensions2016-04-13

💬Community

1
Bugzilla
CVE-2016-1658 chromium-browser: potential leak of sensitive information to malicious extensions2016-04-14
CVE-2016-1658 (MEDIUM CVSS 4.3) | The Extensions subsystem in Google | cvebase.io