CVE-2016-1657 describes a vulnerability in Google Chrome, specifically in the WebContentsImpl::FocusLocationBarByDefault function, affecting versions prior to 50.0.2661.75, as well as Debian, Novell, and OpenSUSE distributions. This flaw allows remote attackers to spoof the address bar through a crafted URL due to mishandled focus for certain about:blank pages. The vulnerability has a CVSS v3 score of 4.3 (Medium), indicating a network-based attack with low attack complexity requiring user interaction, resulting in a low impact on integrity and no impact on confidentiality or availability. Its FAUCET Risk Score is 14/100, and its EPSS score is low, suggesting a low probability of exploitation. There is no evidence of active exploitation, and no public exploit intelligence (Metasploit, Nuclei, ExploitDB) is available. The vulnerability has received minimal community discussion and media coverage, typical for the vast majority of CVEs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
12CPE matchmatch criteria | cpe:2.3:a:novell:suse_package_hub_for_suse_linux_enterprise:12:*:*:*:*:*:*:* | ||
42.1CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:* | ||
<= 49.0.2623.112CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.