CVE-2016-1696

Severity
8.8HIGH
EPSS
1.5%
top 19.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 5
Latest updateMay 14

Description

The extensions subsystem in Google Chrome before 51.0.2704.79 does not properly restrict bindings access, which allows remote attackers to bypass the Same Origin Policy via unspecified vectors.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages7 packages

NVDgoogle/chrome51.0.2704.63
Ubuntuchromium-browser< 51.0.2704.79-0ubuntu0.14.04.1.1121+1
NVDopensuse/leap42.1

Also affects: Debian Linux 8.0, Linux Enterprise 12.0

🔴Vulnerability Details

3
GHSA
GHSA-3r8m-9qvw-p5fw: The extensions subsystem in Google Chrome before 512022-05-14
OSV
CVE-2016-1696: The extensions subsystem in Google Chrome before 512016-06-05
CVEList
CVE-2016-1696: The extensions subsystem in Google Chrome before 512016-06-05

📋Vendor Advisories

1
Red Hat
chromium-browser: cross-origin bypass in extension bindings2016-06-01

💬Community

2
Bugzilla
CVE-2016-1696 chromium-browser: cross-origin bypass in extension bindings2016-06-02
Bugzilla
CVE-2016-2116 jasper: memory leak in jas_iccprof_createfrombuf()2016-03-03
CVE-2016-1696 (HIGH CVSS 8.8) | The extensions subsystem in Google | cvebase.io