CVE-2016-1672: High severity Google Chrome vulnerability
A cross-origin bypass flaw was found in the extension bindings component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=590118
External References:
http://googlechromereleases.blogspot.com/2016/05/stable-channel-update25.html
Other sources
The ModuleSystem::RequireForJsInner function in extensions/renderer/modulesystem.cc in the extension bindings in Google Chrome before 51.0.2704.63 mishandles properties, which allows remote attackers to conduct bindings-interception attacks and bypass the Same Origin Policy via unspecified vectors.
— MITRE
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2016-1673
- CVE-2016-1674
- CVE-2016-1675
- CVE-2016-1676
- CVE-2016-1677
- CVE-2016-1678
- CVE-2016-1679
- CVE-2016-1680
- CVE-2016-1681
- CVE-2016-1682
- CVE-2016-1683
- CVE-2016-1684
- CVE-2016-1685
- CVE-2016-1686
- CVE-2016-1687
- CVE-2016-1688
- CVE-2016-1689
- CVE-2016-1690
- CVE-2016-10403
- CVE-2016-1691
- CVE-2016-1692
- CVE-2016-1693
- CVE-2016-1694
- CVE-2016-1695
Frequently Asked Questions
What is the severity of CVE-2016-1672?
CVE-2016-1672 is rated as high severity due to its potential to allow remote attackers to intercept bindings and bypass the Same Origin Policy.
How do I fix CVE-2016-1672?
To mitigate CVE-2016-1672, update Google Chrome to version 51.0.2704.63 or later.
Which versions of Google Chrome are affected by CVE-2016-1672?
CVE-2016-1672 affects Google Chrome versions prior to 51.0.2704.63.
Can CVE-2016-1672 impact other operating systems beyond Google Chrome?
CVE-2016-1672 is specific to Google Chrome and its versions across different operating systems including Windows, macOS, and Linux.
What types of attacks can exploit CVE-2016-1672?
CVE-2016-1672 can be exploited for bindings-interception attacks that compromise web application security.