CVE-2016-1622
Publication date 14 February 2016
Last updated 25 August 2025
Ubuntu priority
Cvss 3 Severity Score
Description
The Extensions subsystem in Google Chrome before 48.0.2564.109 does not prevent use of the Object.defineProperty method to override intended extension behavior, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| chromium-browser | ||
| 14.04 LTS trusty |
Fixed 48.0.2564.116-0ubuntu0.14.04.1.1111
|
|
| oxide-qt | ||
| 14.04 LTS trusty | Not in release | |
Severity score breakdown
| Parameter | Value |
|---|---|
| Base score |
|
| Attack vector | Network |
| Attack complexity | Low |
| Privileges required | None |
| User interaction | Required |
| Scope | Unchanged |
| Confidentiality | High |
| Integrity impact | High |
| Availability impact | High |
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |