CVE-2016-10696 affects the windows-latestchromedriver project, which downloads chromedriver.exe over unencrypted HTTP, making it susceptible to Man-in-the-Middle (MITM) attacks. This vulnerability carries a CVSS score of 8.1 (High) due to its potential for remote code execution (RCE) if an attacker intercepts the download and substitutes the legitimate binary with a malicious one. The attack complexity is high, but successful exploitation could lead to complete compromise of confidentiality, integrity, and availability. There is no evidence of active exploitation, nor are there known public exploits or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.1.0CPE matchmatch criteria | cpe:2.3:a:windows-latestchromedriver_project:windows-latestchromedriver:0.1.0:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.