First published: Mon Apr 22 2019(Updated: )
A malicious webview could install long-lived unload handlers that re-use an incognito BrowserContext that is queued for destruction in versions of Oxide before 1.18.3.
Credit: security@ubuntu.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oxide Project | <1.18.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1586 is considered to have a moderate severity level.
CVE-2016-1586 affects all versions of Oxide prior to 1.18.3.
To fix CVE-2016-1586, upgrade Oxide to version 1.18.3 or later.
Yes, CVE-2016-1586 can potentially allow a malicious webview to exploit long-lived unload handlers.
Users with affected versions of Oxide may experience security risks related to incognito BrowserContext misuse.