← Back

CVE-2016-1696

nvd nist
Published: Jun 5, 2016Modified: May 6, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

The extensions subsystem in Google Chrome before 51.0.2704.79 does not properly restrict bindings access, which allows remote attackers to bypass the Same Origin Policy via unspecified vectors.

Affected (8)

Products: Google: Chrome · Debian: Debian Linux · Opensuse: Leap, Opensuse · +2 more
Show all products
1 product
Chrome
1 product
Debian Linux
2 products
Leap
Opensuse
3 products
Enterprise Linux Desktop
Enterprise Linux Server
Enterprise Linux Workstation
1 product
Linux Enterprise
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 51.0.2704.63
Configuration B
7 vulnerable
Vulnerable SoftwareAffected Versions
Version 8.0
Version 42.1
Version 13.2
Version 6.0
Version 6.0
Version 6.0
Version 12.0

References (18)

Source: chrome-cve-admin@google.com
Source: chrome-cve-admin@google.com
Source: chrome-cve-admin@google.com
Source: chrome-cve-admin@google.com
Source: chrome-cve-admin@google.com
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.