CVE-2016-1658 PUBLISHED

The Extensions subsystem in Google Chrome before 50.0.2661.75 incorrectly relies on GetOrigin method calls for origin comparisons, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted extension.

EPSS 0.88% · 75.2th percentile

Risk Scores

EPSS Score
0.88%
75.2th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSchromium-browser0, 45.0.2454.101-0ubuntu1.1201, 47.0.2526.73-0ubuntu1.1218
Ubuntu:14.04:LTSchromium-browser37.0.2062.120-0ubuntu0.14.04.1~pkg1049, 38.0.2125.111-0ubuntu0.14.04.1.1061, 39.0.2171.65-0ubuntu0.14.04.1.1064

Timeline

References

Open in Interactive Console →