CVE-2016-1680 is a high-severity use-after-free vulnerability in Skia, specifically within ports/SkFontHost_FreeType.cpp, affecting Google Chrome versions prior to 51.0.2704.63, as well as various Linux distributions including Canonical, Debian, openSUSE, Red Hat, and SUSE. This flaw allows remote attackers to trigger a denial of service through heap memory corruption, with a CVSS v3 score of 8.8, indicating high impact on confidentiality, integrity, and availability. While the vulnerability requires user interaction (UI:R), it can be exploited over the network (AV:N) with low attack complexity (AC:L). There is no evidence of active exploitation, nor are there public exploit modules in Metasploit or ExploitDB, despite some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 50.0.2661.102CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
14.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:* | ||
15.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:* | ||
16.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.