VulnerabilityAnalyzed
CVE-2016-1646
Google Chromium V8 Out-of-Bounds Read Vulnerability
KEVHIGH 8.8EPSS 48.1%
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 22 June 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly consider element data types, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via crafted JavaScript code.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 48.11% probability · 99th percentile
- CISA KEV
- Listed 8 June 2022 · due 22 June 2022
- Weakness
- CWE-125
- Affected
- debian/debian linux · canonical/ubuntu linux · google/chrome · suse/package hub · opensuse/leap · opensuse/opensuse · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux server · redhat/enterprise linux workstation
- Source
- chrome-cve-admin@google.com
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2016-1646
References
- http://googlechromereleases.blogspot.com/2016/03/stable-channel-update_24.htmlRelease Notes, Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00000.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00001.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00039.htmlMailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-0525.htmlThird Party Advisory
- http://www.debian.org/security/2016/dsa-3531Mailing List, Third Party Advisory
- http://www.securitytracker.com/id/1035423Broken Link, Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2955-1Third Party Advisory
- https://code.google.com/p/chromium/issues/detail?id=594574Exploit, Issue Tracking, Mailing List
- https://codereview.chromium.org/1804963002/Patch
- https://security.gentoo.org/glsa/201605-02Third Party Advisory
- http://googlechromereleases.blogspot.com/2016/03/stable-channel-update_24.htmlRelease Notes, Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00000.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00001.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00039.htmlMailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-0525.htmlThird Party Advisory
- http://www.debian.org/security/2016/dsa-3531Mailing List, Third Party Advisory
- http://www.securitytracker.com/id/1035423Broken Link, Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2955-1Third Party Advisory
- https://code.google.com/p/chromium/issues/detail?id=594574Exploit, Issue Tracking, Mailing List
- https://codereview.chromium.org/1804963002/Patch
- https://security.gentoo.org/glsa/201605-02Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-1646US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.