CVE-2016-1648 is a high-severity use-after-free vulnerability in Google Chrome's Extensions implementation, specifically within the GetLoadTimes function. This flaw affects various versions of Google Chrome across Debian and openSUSE distributions. An unauthenticated remote attacker could exploit this vulnerability by enticing a user to visit a malicious website containing crafted JavaScript, leading to a denial of service or potentially arbitrary code execution and data compromise. While there is no public exploit code available in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered significant community discussion and media coverage, indicating awareness and potential interest from threat actors.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 49.0.2623.95CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
13.1CPE matchmatch criteria | cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.