CVE-2016-1646
KEV PoC massOut-of-Bounds Read in Google Chromium V8 JavaScript Engine
CISA: Google Chromium V8 Out-of-Bounds Read Vulnerability
Google's Chromium V8 JavaScript engine contains an out-of-bounds read (CWE-119), meaning the engine reads memory beyond the bounds of an allocated buffer while processing JavaScript. A remote attacker can trigger the flaw by getting a user's browser to execute crafted JavaScript, typically by luring them to a malicious or compromised web page. Successful exploitation primarily causes a denial of service (browser crash), though the advisory notes that other, unspecified impacts may also be possible. Any user of a Chromium-based browser, including Google Chrome, Microsoft Edge, and Opera, was potentially affected while running a vulnerable V8 build. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-06-08 (required action: apply updates per vendor instructions), no public proof-of-concept is known, ransomware use is unknown, and EPSS assigns a 48.1% probability of exploitation within 30 days (99th percentile).
What to do: Apply updates per vendor instructions: bring Google Chrome, Chromium, Opera, and any other Chromium-based browsers or V8-embedding applications up to a current vendor-supported release (this 2016 flaw is remediated in all modern builds). Because the vulnerability is on CISA's KEV list, treat patching of managed and internet-facing systems as required and verify browser/defense versions directly (e.g., via chrome://version or the application's about page) for anything still pinned to 2016-era builds. For products that bundle Chromium or V8 (kiosks, Electron-style apps, appliances), update the bundled engine rather than relying on browser-level updates.
| Google Chromium V8 | — |
| Google Chrome (Chromium-based) | — |
| Microsoft Edge (Chromium-based) | — |
| Opera (Chromium-based) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly consider element data types, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via crafted JavaScript code.
- Affected
- Google Chromium V8
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown