CVE-2016-1586: Input Validation
Published Apr 22, 2019
·Updated
A malicious webview could install long-lived unload handlers that re-use an incognito BrowserContext that is queued for destruction in versions of Oxide before 1.18.3.
Affected Software
1 affected component
Oxide Project Oxide<1.18.3
Remediation
Event History
Apr 22, 2019
CVE Published
via MITRE·03:35 PM
Data Sourced
via MITRE·03:35 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-1586?
CVE-2016-1586 is considered to have a moderate severity level.
2
What versions of Oxide are affected by CVE-2016-1586?
CVE-2016-1586 affects all versions of Oxide prior to 1.18.3.
3
How do I fix CVE-2016-1586?
To fix CVE-2016-1586, upgrade Oxide to version 1.18.3 or later.
4
Can CVE-2016-1586 lead to security vulnerabilities?
Yes, CVE-2016-1586 can potentially allow a malicious webview to exploit long-lived unload handlers.
5
What is the impact of CVE-2016-1586 on users?
Users with affected versions of Oxide may experience security risks related to incognito BrowserContext misuse.