CVE-2016-1677: Infoleak
A type confusion flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=602970
External References:
http://googlechromereleases.blogspot.com/2016/05/stable-channel-update25.html
Other sources
uri.js in Google V8 before 5.1.281.26, as used in Google Chrome before 51.0.2704.63, uses an incorrect array type, which allows remote attackers to obtain sensitive information by calling the decodeURI function and leveraging "type confusion."
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1677?
CVE-2016-1677 has been assigned a moderate severity level due to its potential to expose sensitive information.
How do I fix CVE-2016-1677?
To fix CVE-2016-1677, update affected software to Google Chrome version 51.0.2704.63 or later.
Which versions of Google Chrome are affected by CVE-2016-1677?
CVE-2016-1677 affects Google Chrome versions prior to 51.0.2704.63.
What systems are impacted by CVE-2016-1677?
CVE-2016-1677 impacts various operating systems including Ubuntu, Debian, openSUSE, and Red Hat Enterprise Linux.
What kind of exploit does CVE-2016-1677 involve?
CVE-2016-1677 involves a type confusion vulnerability in the uri.js component of Google V8 affecting the decodeURI function.