Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2016-7189

54
FAUCET Score

CVE-2016-7189 is a remote code execution vulnerability in the Chakra JavaScript engine of Microsoft Edge, allowing attackers to execute arbitrary code via a crafted website. This high-severity flaw (CVSS 7.5) requires user interaction and has a significant impact on confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, it has a high EPSS score and FAUCET Risk Score, indicating a strong likelihood of exploitation. Although no Metasploit or Nuclei exploits exist, an information leak exploit (EDB-40604) is publicly available, and the vulnerability has garnered notable community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

7.5HIGH

CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.6
Impact Score
5.9
CvssVersion
3.0

Exploit Intelligence

EPSS Score
48.13%
Probability of exploitation in next 30 days
EPSS Percentile
98.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
ExploitDB: EDB-40604 · Oct 20, 2016
This CVE's current EPSS score of 0.4813 is in the 93rd percentile among its peer group of 1,572 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

nugetpatch availablevia ghsa
Product: Microsoft.ChakraCoreFixed in: 1.2.1

Vendor Advisories (1)

nugetGHSA-vr4j-gj8q-m89vhigh

ChakraCore RCE Vulnerability

May 14, 2022

References

docs.microsoft.com / en-us/security-updates/securitybulletins/2016/ms16-119
securityfocus.com / bid/93427
securitytracker.com / id/1036993