First published: Sun Feb 14 2016(Updated: )
The Developer Tools (aka DevTools) subsystem in Google Chrome before 48.0.2564.109 does not validate URL schemes and ensure that the remoteBase parameter is associated with a chrome-devtools-frontend.appspot.com URL, which allows remote attackers to bypass intended access restrictions via a crafted URL, related to browser/devtools/devtools_ui_bindings.cc and WebKit/Source/devtools/front_end/Runtime.js.
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
openSUSE | =13.1 | |
Debian Linux | =8.0 | |
Google Chrome | <=48.0.2564.103 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1627 is considered a high-severity vulnerability due to its potential for bypassing access restrictions.
To fix CVE-2016-1627, upgrade to Google Chrome version 48.0.2564.109 or later.
CVE-2016-1627 exploits the lack of validation in the Developer Tools subsystem related to URL schemes.
CVE-2016-1627 affects Google Chrome versions prior to 48.0.2564.109.
Yes, CVE-2016-1627 is present in certain versions of openSUSE 13.1 and Debian 8.0.