CVE-2016-1640 describes a vulnerability in Google Chrome's Web Store inline-installer, specifically within the Extensions UI. This flaw allows remote attackers to trick users into believing an extension installation request originated from a legitimate source by manipulating the installation frame upon deletion. Rated as Medium severity (CVSS 4.3), this vulnerability requires user interaction (UI:R) and could lead to low integrity impact (I:L) by facilitating deceptive installations. There is no evidence of active exploitation, nor are there known public exploit codes or Metasploit modules available. Community discussion and media coverage are minimal, with only one article from SecurityWeek mentioning its fix in Chrome 49.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 48.0.2564.116CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.