CVE-2016-1694: Medium severity google chrome vulnerability
browser/browsingdata/browsingdataremover.cc in Google Chrome before 51.0.2704.63 deletes HPKP pins during cache clearing, which makes it easier for remote attackers to spoof web sites via a valid certificate from an arbitrary recognized Certification Authority.
Other sources
The following flaw was identified in the Chromium browser: hpkp pins removed on cache clearance.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=603682
External References:
http://googlechromereleases.blogspot.com/2016/05/stable-channel-update25.html
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1694?
CVE-2016-1694 has been classified as a moderate severity vulnerability.
How do I fix CVE-2016-1694?
To resolve CVE-2016-1694, upgrade Google Chrome to version 51.0.2704.63 or later.
Which versions of Google Chrome are affected by CVE-2016-1694?
Google Chrome versions prior to 51.0.2704.63 are vulnerable to CVE-2016-1694.
What type of attack does CVE-2016-1694 enable?
CVE-2016-1694 allows remote attackers to spoof websites using valid certificates from recognized Certification Authorities.
Is CVE-2016-1694 specific to any operating systems?
CVE-2016-1694 affects Google Chrome across multiple operating systems, including Red Hat, Debian, and SUSE.