CVE-2016-1690: Use After Free
A heap use-after-free flaw was found in the Autofill component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=608100
External References:
http://googlechromereleases.blogspot.com/2016/05/stable-channel-update25.html
Other sources
The Autofill implementation in Google Chrome before 51.0.2704.63 mishandles the interaction between field updates and JavaScript code that triggers a frame deletion, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted web site, a different vulnerability than CVE-2016-1701.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1690?
CVE-2016-1690 has been assigned a CVSS score indicating a moderate risk of denial of service and potential other impacts.
How do I fix CVE-2016-1690?
To mitigate CVE-2016-1690, update Google Chrome to version 51.0.2704.63 or later.
What type of vulnerability is CVE-2016-1690?
CVE-2016-1690 is a use-after-free vulnerability that affects the Autofill implementation in Google Chrome.
Is CVE-2016-1690 present in older versions of Google Chrome?
Yes, CVE-2016-1690 affects versions of Google Chrome prior to 51.0.2704.63.
What operating systems are vulnerable to CVE-2016-1690?
CVE-2016-1690 impacts several operating systems, including specific versions of Debian and Red Hat Enterprise Linux.