CVE-2016-1701: Use After Free
An use-after-free flaw was found in the Autofill component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=608101
External References:
http://googlechromereleases.blogspot.com/2016/06/stable-channel-update.html
Other sources
The Autofill implementation in Google Chrome before 51.0.2704.79 mishandles the interaction between field updates and JavaScript code that triggers a frame deletion, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted web site, a different vulnerability than CVE-2016-1690.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1701?
CVE-2016-1701 is classified as a high severity vulnerability due to its potential to lead to denial of service and exploit through use-after-free conditions.
How do I fix CVE-2016-1701?
To fix CVE-2016-1701, update Google Chrome to version 51.0.2704.79 or later.
Which versions of Chrome are affected by CVE-2016-1701?
CVE-2016-1701 affects all versions of Google Chrome prior to 51.0.2704.79.
Can CVE-2016-1701 be exploited remotely?
Yes, CVE-2016-1701 can be exploited remotely by attackers to cause a denial of service.
What platforms are impacted by CVE-2016-1701?
CVE-2016-1701 impacts various platforms, including specific versions of Red Hat, Debian, and openSUSE systems.