CVE-2016-1644 describes a use-after-free vulnerability in the WebKit Blink rendering engine, specifically within the LayoutObject.cpp component, affecting Google Chrome versions prior to 49.0.2623.87. This flaw allows remote attackers to trigger a denial of service or potentially achieve further unspecified impact through a specially crafted HTML document. Rated with a CVSS v3 score of 8.8 (HIGH), it requires user interaction (UI:R) but can be exploited over the network (AV:N) with low attack complexity (AC:L), leading to high impacts on confidentiality, integrity, and availability (C:H/I:H/A:H). While there is no known active exploitation (KEV: No) or public exploit code (Metasploit, Nuclei, ExploitDB: None), the vulnerability has garnered significant community discussion and media coverage, indicating notable attention despite its age.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 49.0.2623.75CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.