UBUNTU-CVE-2016-1622

Advisory lineage Upstream: 1 Downstream: 0
Upstream
Published: 14 Feb 2016, 02:59
Last modified:08 Sept 2025, 16:43

Vulnerability Summary

Overall Risk (default)
medium
35/100
CVSS Score
8.8 HIGH
3.0 (osv_ubuntu)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

14 Feb 2016, 02:59
Published
Vulnerability first disclosed
08 Sept 2025, 16:43
Last Modified
Vulnerability information updated

Description

The Extensions subsystem in Google Chrome before 48.0.2564.109 does not prevent use of the Object.defineProperty method to override intended extension behavior, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code.

CVSS Metrics

  • v3.0HIGHScore: 8.8CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Systems

  • ubuntuchromium-browser

    < 48.0.2564.116-0ubuntu0.14.04.1.1111

References (3)