Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2016-1658


The Extensions subsystem in Google Chrome before 50.0.2661.75 incorrectly relies on GetOrigin method calls for origin comparisons, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted extension.


Published

2016-04-18T10:59:07.077

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 4.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-200
    CWE-284

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application novell suse_package_hub_for_suse_linux_enterprise 12 Yes
Operating System opensuse leap 42.1 Yes
Application google chrome ≤ 49.0.2623.112 Yes
Operating System debian debian_linux 8.0 Yes

References