CVE-2016-1670 describes a race condition in Google Chrome's ResourceDispatcherHostImpl::BeginRequest function, affecting Chrome versions prior to 50.0.2661.102, as well as various Debian and OpenSUSE distributions. This medium-severity vulnerability (CVSS 5.3) allows remote attackers to make arbitrary HTTP requests by exploiting a race condition to reuse a request ID, requiring user interaction and high attack complexity. While it has a high integrity impact, there is no evidence of active exploitation, no known public exploit code (Metasploit, Nuclei, ExploitDB), and it is not listed in the KEV catalog. Community discussion and media coverage are minimal, with only one mention and one article found.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 50.0.2661.87CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
13.1CPE matchmatch criteria | cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.