PT-2016-7808 · Google+4 · Google Chrome+4

Guang Gong

·

Published

2016-12-01

·

Updated

2024-06-15

·

CVE-2016-9651

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 55.0.2883.75
Description A missing check in V8 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This issue is related to the handling of private properties of JS objects.
Recommendations For versions prior to 55.0.2883.75, update to version 55.0.2883.75 or later to resolve the issue.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-2425
CVE-2016-9651
DSA-3731-1
MGASA-2016-0419
OPENSUSE-SU-2016_3108-1
OPENSUSE-SU-2017:0563-1
OPENSUSE-SU-2024:10171-1
OPENSUSE-SU-2024:12948-1
RHSA-2016:2919
RHSA-2016_2919
USN-3153-1

Affected Products

Alt Linux
Google Chrome
Red Hat
Suse
Ubuntu