CVE-2016-1667 is a Same Origin Policy bypass vulnerability in the Blink DOM implementation, specifically within the TreeScope::adoptIfNeeded function, affecting Google Chrome versions prior to 50.0.2661.102 and various Debian and OpenSUSE distributions. This high-severity vulnerability (CVSS 8.8) allows remote attackers to execute scripts during node-adoption operations via a crafted website, leading to potential high impact on confidentiality, integrity, and availability. While no public exploit code or active exploitation is reported, the vulnerability garnered some media coverage and community discussion, indicating awareness of its potential.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
13.1CPE matchmatch criteria | cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
<= 50.0.2661.87CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.