CVE-2016-1708 is a use-after-free vulnerability in the Chrome Web Store inline-installation implementation within Google Chrome versions prior to 52.0.2743.82. This flaw allows remote attackers to trigger a denial of service or potentially other unspecified impacts through a crafted website. With a CVSS score of 8.8 (HIGH), it presents a significant risk due to its network-based attack vector and low attack complexity, potentially leading to high confidentiality, integrity, and availability impacts. While there is no known active exploitation or publicly available exploit code in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered notable community discussion and media coverage, indicating awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 51.0.2704.106CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.