CVE-2016-1678: Buffer Overflow
A heap overflow flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=595259
External References:
http://googlechromereleases.blogspot.com/2016/05/stable-channel-update25.html
Other sources
objects.cc in Google V8 before 5.0.71.32, as used in Google Chrome before 51.0.2704.63, does not properly restrict lazy deoptimization, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted JavaScript code.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1678?
CVE-2016-1678 is classified as a moderate severity vulnerability due to its potential for denial of service attacks.
How do I fix CVE-2016-1678?
To fix CVE-2016-1678, update Google Chrome to version 51.0.2704.63 or later.
What impact can CVE-2016-1678 have?
CVE-2016-1678 can lead to a heap-based buffer overflow, resulting in potential denial of service.
Which software versions are affected by CVE-2016-1678?
CVE-2016-1678 affects Google V8 versions up to 5.0.71 and Google Chrome versions up to 50.0.2661.102.
Is there a patch available for CVE-2016-1678?
Yes, a patch is available in the form of the updated Google Chrome version 51.0.2704.63.