CVE-2016-1615 describes a vulnerability in the Omnibox implementation of Google Chrome versions prior to 48.0.2564.82, allowing remote attackers to spoof a document's origin. This medium-severity vulnerability (CVSS 6.5) requires user interaction (UI:R) and could lead to high integrity impact (I:H) without affecting confidentiality or availability. There is no evidence of active exploitation, publicly available exploit code, or inclusion in the CISA KEV catalog. While community discussion and media coverage are present, they are limited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 47.0.2526.106CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.