Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2016-1657

19
FAUCET Score

CVE-2016-1657 describes a vulnerability in Google Chrome, specifically in the WebContentsImpl::FocusLocationBarByDefault function, affecting versions prior to 50.0.2661.75, as well as Debian, Novell, and OpenSUSE distributions. This flaw allows remote attackers to spoof the address bar through a crafted URL due to mishandled focus for certain about:blank pages. The vulnerability has a CVSS v3 score of 4.3 (Medium), indicating a network-based attack with low attack complexity requiring user interaction, resulting in a low impact on integrity and no impact on confidentiality or availability. Its FAUCET Risk Score is 14/100, and its EPSS score is low, suggesting a low probability of exploitation. There is no evidence of active exploitation, and no public exploit intelligence (Metasploit, Nuclei, ExploitDB) is available. The vulnerability has received minimal community discussion and media coverage, typical for the vast majority of CVEs.

Impacted Technologies

VendorProductVersion(s)CPE
8.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
12CPE matchmatch criteria
cpe:2.3:a:novell:suse_package_hub_for_suse_linux_enterprise:12:*:*:*:*:*:*:*
42.1CPE matchmatch criteria
cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*
<= 49.0.2623.112CPE matchmatch criteria
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

4.3MEDIUM

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
1.4
CvssVersion
3.0

Exploit Intelligence

EPSS Score
1.43%
Probability of exploitation in next 30 days
EPSS Percentile
70.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0143 is in the 82nd percentile among its peer group of 26,220 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6 SupplementaryFixed in: chromium-browser-0:50.0.2661.75-1.el6
View patch

Vendor Advisories (1)

redhatCVE-2016-1657Moderate

chromium-browser: address bar spoofing

Apr 13, 2016

References

googlechromereleases.blogspot.com / 2016/04/stable-channel-update_13.html
lists.opensuse.org / opensuse-security-announce/2016-04/msg00040.html
lists.opensuse.org / opensuse-security-announce/2016-04/msg00041.html
lists.opensuse.org / opensuse-security-announce/2016-04/msg00049.html
lists.opensuse.org / opensuse-security-announce/2016-04/msg00050.html
rhn.redhat.com / errata/RHSA-2016-0638.html
codereview.chromium.org / 1678233003
crbug.com / 567445
security.gentoo.org / glsa/201605-02
debian.org / security/2016/dsa-3549