CVE-2016-7549 PUBLISHED

Google Chrome before 53.0.2785.113 does not ensure that the recipient of a certain IPC message is a valid RenderFrame or RenderWidget, which allows remote attackers to cause a denial of service (invalid pointer dereference and application crash) or possibly have unspecified other impact by leveraging access to a renderer process, related to render_frame_host_impl.cc and render_widget_host_impl.cc, as demonstrated by a Password Manager message.

EPSS 0.86% · 75.0th percentile

Risk Scores

EPSS Score
0.86%
75.0th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSchromium-browser47.0.2526.106-0ubuntu1.1221, 48.0.2564.82-0ubuntu1.1222, 48.0.2564.116-0ubuntu1.1229
Ubuntu:14.04:LTSchromium-browser51.0.2704.79-0ubuntu0.14.04.1.1121, 52.0.2743.116-0ubuntu0.14.04.1.1134, 39.0.2171.65-0ubuntu0.14.04.1.1064
Ubuntu:14.04:LTSoxide-qt1.17.7-0ubuntu0.14.04.1, 0, 1.0.0~bzr475-0ubuntu1
Ubuntu:16.04:LTSoxide-qt1.10.3-0ubuntu0.15.10.1, 1.10.3-0ubuntu0.15.10.2, 1.11.3-0ubuntu3

Timeline

References

Open in Interactive Console →