CVE-2016-1635 is a critical use-after-free vulnerability in Google Chrome versions prior to 49.0.2623.75, specifically within the extensions/renderer/render_frame_observer_natives.cc component. This flaw arises from improper handling of object lifetimes and re-entrancy during OnDocumentElementCreated processing. With a CVSS score of 9.8, it allows remote attackers to cause a denial of service or potentially achieve other unspecified impacts through unknown vectors. There is no evidence of active exploitation, publicly available exploit code, or inclusion in the CISA KEV catalog, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 48.0.2564.116CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.