CVE-2016-7549
published 2016-09-25CVE-2016-7549: Google Chrome before 53.0.2785.113 does not ensure that the recipient of a certain IPC message is a valid RenderFrame or RenderWidget, which allows remote…
PriorityP334high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
1.07%
61.7th percentile
Google Chrome before 53.0.2785.113 does not ensure that the recipient of a certain IPC message is a valid RenderFrame or RenderWidget, which allows remote attackers to cause a denial of service (invalid pointer dereference and application crash) or possibly have unspecified other impact by leveraging access to a renderer process, related to render_frame_host_impl.cc and render_widget_host_impl.cc, as demonstrated by a Password Manager message.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | <= 53.0.2785.101 | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qqhx-99jv-jg5r: Google Chrome before 53
ghsa_unreviewed·2022-05-14
CVE-2016-7549 [HIGH] GHSA-qqhx-99jv-jg5r: Google Chrome before 53
Google Chrome before 53.0.2785.113 does not ensure that the recipient of a certain IPC message is a valid RenderFrame or RenderWidget, which allows remote attackers to cause a denial of service (invalid pointer dereference and application crash) or possibly have unspecified other impact by leveraging access to a renderer process, related to render_frame_host_impl.cc and render_widget_host_impl.cc, as demonstrated by a Password Manager message.
OSV
oxide-qt vulnerabilities
osv·2016-10-07·CVSS 8.8
CVE-2016-5170 [HIGH] oxide-qt vulnerabilities
oxide-qt vulnerabilities
A use-after-free was discovered in the V8 bindings in Blink. If a user
were tricked in to opening a specially crafted website, an attacker could
potentially exploit this to cause a denial of service via application
crash, or execute arbitrary code. (CVE-2016-5170)
A use-after-free was discovered in the V8 bindings in Blink. If a user
were tricked in to opening a specially crafted website, an attacker could
potentially exploit this to cause a denial of service via application
crash, or execute arbitrary code. (CVE-2016-5171)
An issue was discovered in V8. If a user were tricked in to opening a
specially crafted website, an attacker could potentially exploit this to
ontain sensitive information from arbitrary memory locations.
(CVE-2016-5172)
Multiple security is
OSV
CVE-2016-7549: Google Chrome before 53
osv·2016-09-25·CVSS 8.8
CVE-2016-7549 [HIGH] CVE-2016-7549: Google Chrome before 53
Google Chrome before 53.0.2785.113 does not ensure that the recipient of a certain IPC message is a valid RenderFrame or RenderWidget, which allows remote attackers to cause a denial of service (invalid pointer dereference and application crash) or possibly have unspecified other impact by leveraging access to a renderer process, related to render_frame_host_impl.cc and render_widget_host_impl.cc, as demonstrated by a Password Manager message.
Ubuntu
Oxide vulnerabilities
vendor_ubuntu·2016-10-07·CVSS 8.8
CVE-2016-5170 [HIGH] Oxide vulnerabilities
Title: Oxide vulnerabilities
Summary: Several security issues were fixed in Oxide.
A use-after-free was discovered in the V8 bindings in Blink. If a user
were tricked in to opening a specially crafted website, an attacker could
potentially exploit this to cause a denial of service via application
crash, or execute arbitrary code. (CVE-2016-5170)
A use-after-free was discovered in the V8 bindings in Blink. If a user
were tricked in to opening a specially crafted website, an attacker could
potentially exploit this to cause a denial of service via application
crash, or execute arbitrary code. (CVE-2016-5171)
An issue was discovered in V8. If a user were tricked in to opening a
specially crafted website, an attacker could potentially exploit this to
ontain sensitive information from arbitr
Red Hat
chromium-browser: DoS via invalid recipient of IPC message
vendor_redhat·2016-09-09·CVSS 8.8
CVE-2016-7549 [HIGH] CWE-476 chromium-browser: DoS via invalid recipient of IPC message
chromium-browser: DoS via invalid recipient of IPC message
Google Chrome before 53.0.2785.113 does not ensure that the recipient of a certain IPC message is a valid RenderFrame or RenderWidget, which allows remote attackers to cause a denial of service (invalid pointer dereference and application crash) or possibly have unspecified other impact by leveraging access to a renderer process, related to render_frame_host_impl.cc and render_widget_host_impl.cc, as demonstrated by a Password Manager message.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-7549 chromium: chromium-browser: DoS via invalid recipient of IPC message [fedora-all]
bugzilla·2016-09-29·CVSS 8.8
CVE-2016-7549 [HIGH] CVE-2016-7549 chromium: chromium-browser: DoS via invalid recipient of IPC message [fedora-all]
CVE-2016-7549 chromium: chromium-browser: DoS via invalid recipient of IPC message [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supp
Bugzilla
CVE-2016-7549 chromium-browser: DoS via invalid recipient of IPC message
bugzilla·2016-09-29·CVSS 8.8
CVE-2016-7549 [HIGH] CVE-2016-7549 chromium-browser: DoS via invalid recipient of IPC message
CVE-2016-7549 chromium-browser: DoS via invalid recipient of IPC message
Google Chrome before 53.0.2785.113 does not ensure that the recipient of a certain IPC message is a valid RenderFrame or RenderWidget, which allows remote attackers to cause a denial of service (invalid pointer dereference and application crash) or possibly have unspecified other impact by leveraging access to a renderer process, related to render_frame_host_impl.cc and render_widget_host_impl.cc, as demonstrated by a Password Manager message.
Upstream bug:
https://codereview.chromium.org/1534933002
References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7549
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1380303]
http://rhn.redhat.com/errata/RHSA-2016-1905.htmlhttp://www.securityfocus.com/bid/93160https://codereview.chromium.org/1534933002https://crbug.com/556351https://crbug.com/646394https://googlechromereleases.blogspot.com/2016/09/stable-channel-update-for-desktop_13.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1905.htmlhttp://www.securityfocus.com/bid/93160https://codereview.chromium.org/1534933002https://crbug.com/556351https://crbug.com/646394https://googlechromereleases.blogspot.com/2016/09/stable-channel-update-for-desktop_13.html
2016-09-25
Published