CVE-2016-1696: High severity google chrome vulnerability
A cross-origin bypass flaw was found in the Extension bindings component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=601073
External References:
http://googlechromereleases.blogspot.com/2016/06/stable-channel-update.html
Other sources
The extensions subsystem in Google Chrome before 51.0.2704.79 does not properly restrict bindings access, which allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1696?
CVE-2016-1696 has a medium severity rating due to its potential to allow cross-origin bypass in Google Chrome.
How do I fix CVE-2016-1696?
To fix CVE-2016-1696, upgrade Google Chrome to version 51.0.2704.79 or later.
What systems are affected by CVE-2016-1696?
CVE-2016-1696 affects Google Chrome versions prior to 51.0.2704.79 across various Linux distributions and platforms.
What is the impact of exploiting CVE-2016-1696?
Exploiting CVE-2016-1696 could allow attackers to bypass the Same Origin Policy, potentially compromising user data.
Are there any known exploits for CVE-2016-1696?
There are no specific public exploits for CVE-2016-1696 known at this time, but the vulnerability poses a risk if not patched.