CVE-2016-1618 describes a vulnerability in Blink, the rendering engine used by Google Chrome prior to version 48.0.2564.82. This flaw involves the improper use of a cryptographically secure random number generator, making it easier for remote attackers to bypass cryptographic protections. With a CVSS v3 score of 6.5 (Medium), this vulnerability could lead to high confidentiality impact through network-based attacks requiring user interaction. There is no evidence of active exploitation, nor are public exploit modules available, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 47.0.2526.106CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.