CVE-2016-1648: Use After Free
Use-after-free vulnerability in the GetLoadTimes function in renderer/loadtimesextensionbindings.cc in the Extensions implementation in Google Chrome before 49.0.2623.108 allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1648?
CVE-2016-1648 is classified as a high severity vulnerability that can lead to denial of service or other impacts.
How do I fix CVE-2016-1648?
To resolve CVE-2016-1648, update Google Chrome to version 49.0.2623.108 or later.
What causes CVE-2016-1648?
CVE-2016-1648 is caused by a use-after-free vulnerability in the GetLoadTimes function within Chrome's Extensions implementation.
Which software is affected by CVE-2016-1648?
CVE-2016-1648 affects Google Chrome versions before 49.0.2623.108, as well as openSUSE 13.1 and Debian 8.0.
Can CVE-2016-1648 be exploited remotely?
Yes, CVE-2016-1648 can be exploited remotely through crafted JavaScript code.