CVE-2016-1708
published 2016-07-23CVE-2016-1708: The Chrome Web Store inline-installation implementation in the Extensions subsystem in Google Chrome before 52.0.2743.82 does not properly consider object…
PriorityP432high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
1.00%
59.2th percentile
The Chrome Web Store inline-installation implementation in the Extensions subsystem in Google Chrome before 52.0.2743.82 does not properly consider object lifetimes during progress observation, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted web site.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | <= 51.0.2704.106 | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
chromium-browser: use-after-free in extensions
vendor_redhat·2016-07-20·CVSS 8.8
CVE-2016-1708 [HIGH] chromium-browser: use-after-free in extensions
chromium-browser: use-after-free in extensions
The Chrome Web Store inline-installation implementation in the Extensions subsystem in Google Chrome before 52.0.2743.82 does not properly consider object lifetimes during progress observation, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted web site.
GHSA
GHSA-wh63-8v37-7r3j: The Chrome Web Store inline-installation implementation in the Extensions subsystem in Google Chrome before 52
ghsa_unreviewed·2022-05-17
CVE-2016-1708 [HIGH] CWE-416 GHSA-wh63-8v37-7r3j: The Chrome Web Store inline-installation implementation in the Extensions subsystem in Google Chrome before 52
The Chrome Web Store inline-installation implementation in the Extensions subsystem in Google Chrome before 52.0.2743.82 does not properly consider object lifetimes during progress observation, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted web site.
OSV
CVE-2016-1708: The Chrome Web Store inline-installation implementation in the Extensions subsystem in Google Chrome before 52
osv·2016-07-23·CVSS 8.8
CVE-2016-1708 [HIGH] CVE-2016-1708: The Chrome Web Store inline-installation implementation in the Extensions subsystem in Google Chrome before 52
The Chrome Web Store inline-installation implementation in the Extensions subsystem in Google Chrome before 52.0.2743.82 does not properly consider object lifetimes during progress observation, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted web site.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-1708 chromium-browser: use-after-free in extensions
bugzilla·2016-07-21·CVSS 8.8
CVE-2016-1708 [HIGH] CVE-2016-1708 chromium-browser: use-after-free in extensions
CVE-2016-1708 chromium-browser: use-after-free in extensions
An use-after-free flaw was found in the Extensions component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=613949
External References:
https://googlechromereleases.blogspot.com/2016/07/stable-channel-update.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2016:1485 https://rhn.redhat.com/errata/RHSA-2016-1485.html
Checkpoint
26th February – Threat Intelligence Report
blogs_checkpoint·2024-02-26
CVE-2024-1708 26th February – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 26th February – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 26th February, please download our Threat_Intelligence Bulletin .
TOP ATTACKS AND BREACHES
The American Prince George’s County Public Schools (PGCPS) has experienced a ransomware attack that compromised the personal data of nearly 100K individuals. The attack exposed individuals’ full names, financial account information, and Social Security Numbers. The Rhysida ransomware gang is reportedly responsible for t
http://googlechromereleases.blogspot.com/2016/07/stable-channel-update.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00022.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00028.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1485.htmlhttp://www.debian.org/security/2016/dsa-3637http://www.securityfocus.com/bid/92053http://www.securitytracker.com/id/1036428https://codereview.chromium.org/2103663002https://crbug.com/613949http://googlechromereleases.blogspot.com/2016/07/stable-channel-update.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00022.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00028.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1485.htmlhttp://www.debian.org/security/2016/dsa-3637http://www.securityfocus.com/bid/92053http://www.securitytracker.com/id/1036428https://codereview.chromium.org/2103663002https://crbug.com/613949
2016-07-23
Published