CVE-2016-8508 describes a vulnerability in Yandex Browser for desktop versions prior to 17.1.1.227, where the browser's "Protect" feature (similar to Google Safe Browsing) fails to display security warnings on websites with specific content types. This flaw could allow a remote attacker to prevent users from seeing warnings on malicious sites. The vulnerability has a CVSS v3.1 score of 6.5 (Medium), indicating a network-based attack requiring user interaction, with a high impact on integrity but no impact on confidentiality or availability. There is no evidence of active exploitation, no public exploit code available (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 17.1.1.227CPE matchmatch criteria | cpe:2.3:a:yandex:yandex_browser:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.