CVE-2016-1687

Severity
6.5MEDIUM
EPSS
2.2%
top 15.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 5
Latest updateMay 14

Description

The renderer implementation in Google Chrome before 51.0.2704.63 does not properly restrict public exposure of classes, which allows remote attackers to obtain sensitive information via vectors related to extensions.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages7 packages

NVDgoogle/chrome50.0.2661.102
Ubuntuchromium-browser< 51.0.2704.79-0ubuntu0.14.04.1.1121+1
NVDopensuse/leap42.1

Also affects: Debian Linux 8.0, Linux Enterprise 12.0

🔴Vulnerability Details

3
GHSA
GHSA-89h7-p99q-pwx5: The renderer implementation in Google Chrome before 512022-05-14
CVEList
CVE-2016-1687: The renderer implementation in Google Chrome before 512016-06-05
OSV
CVE-2016-1687: The renderer implementation in Google Chrome before 512016-06-05

📋Vendor Advisories

1
Red Hat
chromium-browser: information leak in extensions2016-05-25

💬Community

2
Bugzilla
CVE-2016-1687 chromium-browser: information leak in extensions2016-05-26
Bugzilla
CVE-2016-2116 jasper: memory leak in jas_iccprof_createfrombuf()2016-03-03
CVE-2016-1687 (MEDIUM CVSS 6.5) | The renderer implementation in Goog | cvebase.io