CVE-2016-1617 describes a vulnerability in the Content Security Policy (CSP) implementation of Blink, specifically within the CSPSource::schemeMatches function, affecting Google Chrome versions prior to 48.0.2564.82. This flaw allowed remote attackers to infer if a user had visited a specific HSTS website by observing CSP reports, due to improper application of http/ws policies to https/wss URLs. Rated with a CVSS score of 4.3 (MEDIUM), the vulnerability requires user interaction (UI:R) and has a low impact on confidentiality (C:L), with no impact on integrity or availability. There is no evidence of active exploitation, publicly available exploit code, or Metasploit/Nuclei modules, though it garnered some community discussion and media coverage at the time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 47.0.2526.106CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.