PT-2016-2657 · Google+4 · Google Chrome+4

Adam Varsan

·

Published

2016-07-20

·

Updated

2024-06-15

·

CVE-2016-1708

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 52.0.2743.82
Description The issue is related to the implementation of the Chrome Web Store inline-installation in the Extensions subsystem, which does not properly consider object lifetimes during progress observation. This allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted web site.
Recommendations For versions prior to 52.0.2743.82, update to version 52.0.2743.82 or later to resolve the issue. As a temporary workaround, consider restricting access to the Chrome Web Store or disabling the inline-installation feature until a patch is applied. Avoid using the Extensions subsystem in Google Chrome until the issue is resolved.

Fix

DoS

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-2194
BDU:2016-02049
CVE-2016-1708
DSA-3637-1
MGASA-2016-0274
OPENSUSE-SU-2016:1868-1
OPENSUSE-SU-2016:1869-1
OPENSUSE-SU-2016_1865-1
OPENSUSE-SU-2016_1869-1
OPENSUSE-SU-2016_1918-1
OPENSUSE-SU-2024:10171-1
OPENSUSE-SU-2024:12948-1
RHSA-2016:1485
RHSA-2016_1485

Affected Products

Alt Linux
Google Chrome
Opera
Red Hat
Suse