CVE-2016-9650: Medium severity Google Chrome vulnerability
Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android incorrectly handled iframes, which allowed a remote attacker to bypass a no-referrer policy via a crafted HTML page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9650?
The severity of CVE-2016-9650 is classified as high due to its potential to allow remote attackers to exploit the vulnerability.
How do I fix CVE-2016-9650?
To fix CVE-2016-9650, update Google Chrome to version 55.0.2883.75 or later on Mac, Windows, and Linux, and version 55.0.2883.84 or later on Android.
What does CVE-2016-9650 affect?
CVE-2016-9650 affects versions of Google Chrome prior to 55.0.2883.75 for desktop platforms and prior to 55.0.2883.84 for Android.
How can CVE-2016-9650 be exploited?
CVE-2016-9650 can be exploited by a remote attacker using a crafted HTML page that bypasses the no-referrer policy through incorrect iframe handling.
Is CVE-2016-9650 a persistent vulnerability?
CVE-2016-9650 is not a persistent vulnerability as it requires user interaction to exploit via a specially crafted webpage.