ZeroHour

CVE-2016-1625

CVSS 3.0
4.3 medium
EPSS
1%p66
Published
()
Modified
Description

The Chrome Instant feature in Google Chrome before 48.0.2564.109 does not ensure that a New Tab Page (NTP) navigation target is on the most-visited or suggestions list, which allows remote attackers to bypass intended restrictions via unspecified vectors, related to instant_service.cc and search_tab_helper.cc.

Vendors
opensusegoogledebian
Products
opensuse, chrome, debian linux
Weakness
CWE-264
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.