CVE-2016-1632

The Extensions subsystem in Google Chrome before 49.0.2623.75 does not properly maintain own properties, which allows remote attackers to bypass intended access restrictions via crafted JavaScript code that triggers an incorrect cast, related to extensions/renderer/v8_helpers.h and gin/converter.h.
Configurations

Configuration 1 (hide)

cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

History

07 Nov 2023, 02:30

Type Values Removed Values Added
References (GENTOO) https://security.gentoo.org/glsa/201603-09 - () https://security.gentoo.org/glsa/201603-09 -
References (SUSE) http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00015.html - () http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00015.html -
References (SUSE) http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00014.html - () http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00014.html -
References (SUSE) http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00018.html - () http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00018.html -
References (BID) http://www.securityfocus.com/bid/84008 - () http://www.securityfocus.com/bid/84008 -
References (CONFIRM) https://codereview.chromium.org/1433293004 - () https://codereview.chromium.org/1433293004 -
References (CONFIRM) https://code.google.com/p/chromium/issues/detail?id=549986 - () https://code.google.com/p/chromium/issues/detail?id=549986 -
References (DEBIAN) http://www.debian.org/security/2016/dsa-3507 - () http://www.debian.org/security/2016/dsa-3507 -
References (CONFIRM) http://googlechromereleases.blogspot.com/2016/03/stable-channel-update.html - Vendor Advisory () http://googlechromereleases.blogspot.com/2016/03/stable-channel-update.html -
References (SUSE) http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00028.html - () http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00028.html -
References (SECTRACK) http://www.securitytracker.com/id/1035185 - () http://www.securitytracker.com/id/1035185 -

Information

Published : 2016-03-06 02:59

Updated : 2023-12-10 11:46


NVD link : CVE-2016-1632

Mitre link : CVE-2016-1632

CVE.ORG link : CVE-2016-1632


JSON object : View

Products Affected

google

  • chrome
CWE
CWE-264

Permissions, Privileges, and Access Controls