CVE-2016-1664
Severity
4.3MEDIUM
EPSS
1.1%
top 22.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 14
Latest updateMay 14
Description
The HistoryController::UpdateForCommit function in content/renderer/history_controller.cc in Google Chrome before 50.0.2661.94 mishandles the interaction between subframe forward navigations and other forward navigations, which allows remote attackers to spoof the address bar via a crafted web site.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4
Affected Packages5 packages
Also affects: Enterprise Linux 6.0, 6.7z
🔴Vulnerability Details
3GHSA▶
GHSA-cmvc-m67j-8h9m: The HistoryController::UpdateForCommit function in content/renderer/history_controller↗2022-05-14
OSV▶
CVE-2016-1664: The HistoryController::UpdateForCommit function in content/renderer/history_controller↗2016-05-14
CVEList▶
CVE-2016-1664: The HistoryController::UpdateForCommit function in content/renderer/history_controller↗2016-05-14