CVE-2016-1680: Buffer Overflow
A heap use-after-free flaw was found in the Skia component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=589848
External References:
http://googlechromereleases.blogspot.com/2016/05/stable-channel-update25.html
Other sources
Use-after-free vulnerability in ports/SkFontHostFreeType.cpp in Skia, as used in Google Chrome before 51.0.2704.63, allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via unknown vectors.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1680?
CVE-2016-1680 has a severity rating that can lead to denial of service and potential heap memory corruption.
How do I fix CVE-2016-1680?
To fix CVE-2016-1680, update Google Chrome to version 51.0.2704.63 or later.
Which versions of Google Chrome are affected by CVE-2016-1680?
CVE-2016-1680 affects Google Chrome versions prior to 51.0.2704.63.
What type of vulnerability is CVE-2016-1680?
CVE-2016-1680 is a use-after-free vulnerability found in the Skia graphics library used by Google Chrome.
Can CVE-2016-1680 be exploited remotely?
Yes, CVE-2016-1680 can be exploited remotely to cause denial of service or potentially other unspecified impacts.